> While Active Directory does allow LDAP binds with the UPN, it doesn't appear > to be supported on all versions. > It's possible we'll recommend using the the bindSearchAuthenticator for AD > instances going forward and there's certainly nothing wrong with using that > approach now. +1, anything to reduce differentiation is better to me. -- Scott