Chapter 3 Authentication for FortiOS 5.0 : Authentication servers : LDAP servers : Example of LDAP to allow Dial-in through member-attribute - CLI
  
Example of LDAP to allow Dial-in through member-attribute - CLI
In this example, users defined in MicroSoft Windows Active Directory (AD) are allowed to setup a VPN connection simply based on an attribute that is set to TRUE, instead of based on being part of a specific group.
In AD, the “Allow Dial-In” property is activated in the user properties, and this sets the msNPAllowDialin attribute to TRUE.
This same procedure can be used for other member attributes, as your system requires.