Howard,

The script is not returning the correct information from our AD.

I think it may have to do with using WinNT rather then LDAP: calls as my testing is using Universal Groups which WinNT does not understand.

If I get a chance I'll look into it further this week.