> The 'WHAT I HAVE SO FAR' triggers the password-expiry, irrespective of
> whether user is in the memberOf ou=foo,dc=example,dc=edu.

Without much study,

* You have an AND there with nothing inside it but one predicate, which doesn't really make sense, so may be a sign of something but I don't know what. It shouldn't break it, it's just odd.

* I think you have the check backwards, since as documented the condition has to be false if you want the warning to happen.

-- Scott

