When a user adds an LDAP query to populate users from an AD group, he selects users to add and gets the following error "Generic service error occurred: Object reference not set to an instance of an object."
The issue is that FIPS (Federal Information Processing Standards) is enabled in the global policy.
Turning off FIPS will let the customer add users.