need help - connection to ms active directory

hello all

I’m using turnkey suitecrm ,
and trying to connect to my enterprise AD and it doesn’t look like its working

first how does it works ?
lets say that I did bind to AD,
do I need to create an employee ?
can a AD user login to suitecrm with his AD user and pass without suitecrm admin create a user for him ?
can I convert an existing employee to an AD user ?

username and password are correct
I checked that I can telnet successfully from suitecrm server the DC at port 389
what is the user filter ?
is suitecrm is sso enabled ?

thank you

bumping up