We specify multiple AD groups in "Group base DN" field under "Group settings" as 'cn=admingrp,ou=...;cn=usergrp,ou=...'. We do not use "Static group search filter.
The groups are then mapped to each local Splunk role for access control.
The "User base filter" is defined as follow:
(&(objectCategory=Person)(sAMAccountName=*))
... View more