http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/412/cas/s_adsso.html#wp1155714
Step 9
Search Filter—The attribute to be authenticated. The search attribute to be matched with any user in the base of the LDAP tree. For example:
•
CN=$user$, or
•
uid=$user$, or
•
sAMAccountName=$user$