Using nested AD groups to filter access to Gitlab

I struggled while trying to limit access to our internal omnibus Gitlab instance using the LDAP-setting user_filter:. We use nested groups in Microsoft AD to handle users and access rights, which works with Gitlab, when you know about the secret sauce. Licensing - you need an enterprise license First I tried getting it to work with our Gitlab instance »