The Bind DN user, such as Administrator, is the username associated with the Bind DN user account.
For a single domain Active Directory Domain Service, the Bind DN entry must be located in the same branch and below the Base DN.
For a multi-domain Active Directory Domain Service (AD DS) forest, because you leave the Base DN text box empty, the restrictions that apply for a single domain do not apply for a multi-domain forest.
ClearPass fills in the domain portion of the Bind DN.
Bin mir nicht sicher ob das dir weiterhilft aber einen Versuch wäre es wert.
Quelle Punkt 4:
Adding Active Directory as an Authentication Source to ClearPass