You will need the following:
This can either be microfocus-MFDS-User (supplied by Micro Focus), if ES users will be separate from Windows users, or user (supplied by Microsoft and modified by Micro Focus) to use your Windows user accounts for ES. (Shown as userclass below.)
Normally, this will be the fully-qualified domain name of the AD host, minus the hostname, with each segment of the name listed as a separate DC element, so for example server.dept.mydom.com would use DC=dept,DC=mydom,DC=com. If you are using ADAM, you may want to use the default domain DN for ES LDAP data, which is "CN=Micro Focus,CN=Program Data,DC=local".
ES groups and resources are used only by ES, so we recommend you use the defaults (located in CN=Micro Focus,CN=Program Data) for their containers.
If you are using the Micro Focus user class (microfocus-MFDS-User), you can use the default ES user container (CN=Enterprise Server Users,CN=Micro Focus,CN=Program Data, below the domain-DN) as well.
On the other hand, if you want to let existing Windows users sign on to ES without creating separate ES user accounts for them, you will need to configure ES to use your existing user container in AD (usually CN=Users). Use that for your user container (shown as user-container below) in the following commands as well.