I have had a succesful connection towards the very same AD server from a WF24 using the legacy security, sample from standalone-full.xml below.
The WF is making the query to the AD and the authentication (user+pass) works OK
Have you successfully connected a WF26+Elytron towards an MSAD, I would love to take a peek at your standalone....xml section
Thanks in advance.
<login-module code="LdapExtended" flag="optional">
<module-option name="java.naming.factory.initial" value="com.sun.jndi.ldap.LdapCtxFactory"/>
<module-option name="java.naming.provider.url" value="ldap://
myserver.com:389"/>
<module-option name="java.naming.referral" value="follow"/>
<module-option name="java.naming.security.authentication" value="simple"/>
<module-option name="bindDN" value="MYDOMAIN\ldap_user"/>
<module-option name="bindCredential" value="secret"/>
<module-option name="baseCtxDN" value="dc=ismobile,dc=ismobilehq,dc=com"/>
<module-option name="baseFilter" value="(&(sAMAccountName={0})(objectclass=User))"/>
<module-option name="rolesCtxDN" value="dc=ismobile,dc=ismobilehq,dc=com"/>
<module-option name="roleFilter" value="(member={1})"/>
<module-option name="roleAttributeID" value="memberOf"/>
<module-option name="roleAttributeIsDN" value="true"/>
<module-option name="roleNameAttributeID" value="cn"/>
<module-option name="allowEmptyPasswords" value="false"/>
<module-option name="roleRecursion" value="-1"/>
<module-option name="searchScope" value="SUBTREE_SCOPE"/>
<module-option name="unauthenticatedIdentity" value="anonymous"/>
</login-module>