Now you can log on only, when account is created in particular children domain which must be setup on LDAP authentication. You can’t log on when user are in different children domain or use root domain in search base. It will be great when it will be possible to log on from different subdomains.