>> serviceSearchDescriptor: group: ou=group,dc=foo,dc=com Did you create this "ou=group,dc=foo,dc=com", because default FDS has a "ou=Groups,dc=foo,dc=com". I used that one, by adding the "posixgroup" object to "ou=Groups,dc=foo,dc=com" and adding the following attribute to the profile. NS_LDAP_SERVICE_SEARCH_DESC= group: ou=Groups,dc=foo,dc=com