What is the best way to select attributes for all members of an AD LDAP group from PHP?

Hard to tell, but typically, LDAP result code (1) indicates that the associated request was out of sequence with another operation in progress (e.g. , a non-bind request in the middle of a multi-stage SASL bind). It does not indicate that the client has sent an erroneous message.

I'm not sure where exactly is the problem, in the filter or the attributes selection. If it's the attribution selection. If it's the filter, then I suggest you put the attribute selection aside now as a way of isolating the problem.

