>> Have you configured /etc/nsswitch.conf to look up active directory
>> groups (presumably via nss_ldap)?

> I have not configured LDAP for this task. I do have winbind configured
> though for Samba Authentication. Do I have to setup LDAP also to all
> group specification in the SSHD config?

sshd just uses getgrouplist() (or the equivalent getgrent() calls) to
determine which groups a given user is in. As long as the "groups"
part of nsswitch.conf is set up and works correctly then sshd should
be able to use it. (I have not used winbind so I'm not sure what steps
are required in order to do this, though.)

