Just for remember - every account created in ADAM/LDS is disabled by default. There is the dedicated attribute ms-DS-User-Account-Disabled which should be - if we want to use this account to login/authenticate - switch from default 'true' to 'false'. I spent too many hours to guess why I've got strange LDAP errors 49 with strange codes and sometime message said that is something wrong with account.
