LDAP integration query

Hi CBunge ,
Thanks for response,
actually what we want to achive is create group of user with cn inside ou, and only allow those particular user with specified cn able to login.
I found discussion reference below

But when I put parameter “USER DN EXPRESSION” with cn specified as above discussion reference cn=$username,cn=group,ou=ou1,dc=tc,dc=local, it always give error, and couldnt do SAVE CHANGES.

Any insight?