Filtering on OU would be awesome! Except it is impossible. The only two attributes that have the OU are distinguishedName and cn and LDAP search filters on AD will not allow you do partial attribute (ie. using an *) searches on those two attributes.