On 11/23/2015 10:07 PM, Adam Young wrote: > What kind of diagnostic tooling do we need? I know the basics: > > If I have a known good user in LDAP, can they . This is the first > thing, and it can be done by asking for an unscoped token. Certainly if you have a known good user in LDAP, they can . Best, -jay