Thread:Extension talk:LDAP Authentication/error if i define more than 1 group in $wgLDAPBaseDNs/reply

That isn't supported. LDAP client calls don't even support that, so the plugin has no way of doing so. If you want to search more than one OU, you need to set the base dn to a higher OU in the tree (in this case, o=AUTH).

If you want to restrict access to specific sets of people, you'll need to use groups, and do group restrictions or group synchronization.