It actually turned out to be a permissions issue. The domain-based service account I was using to bind to Active Directory did not have the ability to view all permissions on a user object, such as group membership. The KB article below helped me resolve this: