Yes. Try making the cachepilot LDAP user account a member of 'Domain Admins'. If that doesn't work straight away, try these instructions:
1.Create a group in AD called 'cache'.
2. Create a user in AD called 'cacheadmin' in the 'Users' container. This account needs to be a member of 'Domain Admins' and the 'Cache' group created earlier.
3.On the cachepilot LDAP configuration page, configure the settings as follows:
LDAP Server: IP address of DC.
User Directory: Base DN of AD Domain (e.g. DC=reephamhigh,DC=local)
User: cacheadmin, CN=Users
Password: password for cacheadmin
4.On the cachepilot 'User' page, add a user called 'cache' (the same as the AD group created earlier) and make the user a member of the cachepilot 'controlled' group.
5.On the cachepilot 'Web Access' page, change the radio button to 'Users'.
6.In Active Directory, user accounts need to be added to the 'cache' group to be able to authenticate and access the internet.
Issues:
UPN suffixes are not supported.
Users that have been renamed in the past cannot authenticate.
Users with spaces or other non-alphanumeric characters in their passwords cannot authenticate.