Note:
The CMS user ID maps to the Active Directory user or person objectClass: sAMAccountName field. The CMS user ID field supports 31 characters. However, for LDAP-authenticated users, you are limited to 20 characters. You cannot use special characters including hyphens, underscores, punctuation, and any diacritical, accented, special characters or blanks (for example, á, ñ, ç, |).
Verify that the username is configured in a user or person objectClass and that the username is in the sAMAccountName field. Verify that the names match exactly (spelling, capitalization, no unexpected spaces, and so on.)