You can use the following identity map for usernames expressed in Windows NT logon format, for example: td\ab111222.
<Mechanism Name="ldap"> <MechanismProperties ... /> <IdentityMap Match="[Tt][Dd]\\(.+)" Pattern="cn=${1},ou=users,dc=td,dc=teradata,dc=com"/> </Mechanism>
This identity map extracts no domain information from the username, but instead uses information in the Pattern attribute to construct the DN.