Groups via AD

So I loaded 3.7 and have it authenticating via AD … seems to be working fine … but in our system our User Groups are in a “branch” than our users … so I have sort of GROUPS, SITE, COMPANy.COM for groups and USERS, SITE, COMPANY.COM for users … I used the later as my BASE DN to get my users. Under SITE I have several CNs that I did not want accounts getting set up for … machine accounts, test accounts, resource accounts , etc…

So now I have no groups… Any solutions?