So...
Ok.
Most of that went over my head.

So, basically, there is no simple way to implement a simple query on OUs?

If I setup groups in the active directory, and added members to those groups using the Member Of tab in the user properties... the in group statements would work?