Thank you all for the helpful advice. I have had some trouble trying to import the Active DS Type Library (registry problem), but nothing that cannot be sorted out today. In the meantime, following your general reading suggestions, I have been able to use ADO to access LDAP through OpenQuery and now have a working two-stage authentication process, first to check that the username/password combination is valid, then to verify membership and permissions within an AD group. Actually didn't take me nearly as long as I had feared it might, and although the current solution is probably not the best it will suffice until I can fix the other problems and familiarise myself further with the workings of AD. Thanks again for your helpful replies.