Thanks by your response Steve, I changed config to: <AuthBy LDAP2> Host XXX SSLVerify none UseTLS Port 3268 AuthDN XXX AuthPassword XXX BaseDN dc=XXX,dc=XXX Scope sub ServerChecksPassword UsernameAttr sAMAccountName NoDefault AuthAttrDef logonHours,MS-Login-Hours,check </AuthBy> And it works nicely !! -- js