Re: rewrite a login into a dn in simple bind

> You could avoid the configuration issue, if you save the dn of this
> group somewhere in a "special" place in the server - don't know, if the
> rootDSE is applicable for that. (But you have to configure your
> application anyway - at least the base-dn and the server name - so one
> more configuration option will be no problem.)

Just build your application to perform server location via SRV records. 
This is a standard, works very well, and SRV records are supported by
ever modern DNS server.  If you have M$ clients you probably have SRV
records already anyway (With AD they are created automatically).