Refreshing LDAP group failed with the following error for certain user.
PAM-LDAP-0018: Error Adding user CN= ... PAM-CMN-0234: User add failed
Release: PAM 4.1.x
We found the email assigned to the AD user is not in correct format in AD side. After fixing the email data or removing it, re-refreshing the LDAP group resolves the problem.