Michael I'm not sure whether I unterstand the problem as I don't user web auth.
Here a example how I check whether a user is in the correct AD group...
To get the Secure-Home Rule the user must be in my AD group "Team".
memberOf ==> CN=Team,OU=Team,DC=mywlan,DC=at