Block AD logins

When setting up openfire server i set my base dn to be the main part of my domain (gcon). The issue I have run into is that I don’t want anyone to be able to login and use spark. I have shared out a few of the groups but want to restrict so that we don’t have (non-admins) using the software.

Do i need to change my base dn to the OU that has the group in it or can i use a plugin to block the ability the login except for certain groups.

create an access group and then use ldap filter that will use that group for user access.