It's protocol extension is very useful for query the user with his list of security groups GUID, in a single request More info: https://msdn.microsoft.com/en-us/library/aa366980(v=vs.85).aspx http://ldap3.readthedocs.io/ldap3.protocol.microsoft.html#ldap3.protocol.microsoft.ExtendedDN https://github.com/noirello/bonsai/issues/6