By default an AD domaincontroller implements a querylimit of 1000 results. This limit is reconfigurable on a systemlevel @DC (which most admins don’t want to change) and on a connectionlevel.
We would like to see this limit as a configuration setting of the usersystem definition.
ps: on the (windows) command set for managing the AD this is the -limit parameter.
We tested this and the primary usersystem only reads the first 1000 entries.
At the moment we testing/comparing Searchdaimon against other open source ES.
We have a AD-forest with about 32000 users accounts.