Thanks for the quick reply Phillip. Yes, we get the green check mark. I forgot to mention, on the clients page I do see that users are being identified, it's just that the list of AD groups never populates when we hit "refresh ldap groups". I'm not familar with ldapsearch, I can give it a go. We did try ldp.exe and it seems we're able to connect to ldap over SSL. No idea where we're going wrong here. Checked the event viewer on the domain controllers, didn't see anything that seemed related to this. Checked the event log on the meraki appliance and other than 'connected to domain controller' I don't see any messaging related to this process.
... View more