This is what I have setup for OpenLDAP, if it helps.
In OpenLDAP it uses multiple memberUid's for members of groups.
[image: 1580553913022-ldap-group-membership.png]
These setting seem to work with my limited testing and knowledge.
[image: 1580553913353-veyon-env-settings.png]
I changed the group member identification and filtered objects on the different OU's and then used the test to ensure I got back the right objects.
[image: 1580553913172-veyon-advanced-settings.png]