Hi kkwan,
The documentation for setting up LDAP is a bit misleading. We're getting it corrected. The documentation instructs you to drop the base DN when setting up your LDAP User Groups. This is incorrect. You must include the base DN in your hierarchy.
To use the help documentation example, if your user is "CN=John Smith,OU=Marketing,OU=Tampa Office,OU=Blue Division,DC=myoffice,DC=net" then the hierarchy for your LDAP User Groups should be net -> myoffice -> Blue Division -> Tampa Office -> Marketing.
Hope that helps,
Peter