Judging by your screen-shot, you haven't provided a user path. pick one of your AD users that can't log in and find their location in Active Directory. Provide this location in your LDAP UME config and restart the system... then try to log in again with that user.
<KC>