Matching the syntax of your accounts and groups is crucial for LDAP requests. You can find the proper synatax for your user or group by using the "Distinguished Name" field in "Active Directory Users and Computers". Open up "Active Directory Users and Computers" and right click on your root domain. Choose the "Find" option from the pop-up menu. From the drop-down menu "View" select "Choose Columns" and then add the column for "Distinguished Name". Search for your account. In this example we have a user with the word Palo in the name. The search box will show you the syntax for an LDAP query (example: CN=xxxxxx, OU=yyyyyy, DC=com). This will have your specific information required for the Palo Alto.
... View more