Hello
Thank you for your question and reaching out. I can understand you are having query\issues related to use Protected Users Group to authenticate in ldap.
Please note that Protected users have some restrictions as listed below. Hence please use non-protected users account in your LDAP query.
If the domain functional level is Windows Server 2012 R2 , members of the group can no longer:
Authenticate by using NTLM authentication
Use Data Encryption Standard (DES) or RC4 cipher suites in Kerberos pre-authentication
Be delegated by using unconstrained or constrained delegation
Renew user tickets (TGTs) beyond the initial 4-hour lifetime
Reference :
--If the reply is helpful, please Upvote and Accept as answer--