> But is there a similar syntax that will allow me to define access based on AD > groups? > > Something like allow {$group_Domain Admins}? There's an automatic tag generated for each LDAP group of the user, {$lgcn_group_name}. However, this is a kind of a hack (which is typical for authentication code though). -- Denis Ovsienko