Michael I'm not sure whether I unterstand the problem as I don't user web auth.
Here a example how I check whether a user is in the correct AD group...
To get the Secure-Home Rule the user must be in my AD group "Team".
memberOf ==> CN=Team,OU=Team,DC=mywlan,DC=at
![47b030a898da46f59772a5ba038a3229_RackMultipart20140725-1712-1uz7nrw-LDAP_group_inline.png 47b030a898da46f59772a5ba038a3229_RackMultipart20140725-1712-1uz7nrw-LDAP_group_inline.png](/t5/image/serverpage/image-id/274i064282CB58147094/image-size/large?v=v2&px=999)