Actually, on closer review, it is logging them in but it's not associating the group membership properly (hence it's not letting me log them into the administration section).
Under "User Source - LDAP", I've defined the following group map:
CN=Domain Admins,CN=Users,DC=my,DC=domain,DC=com;24;Administrator;100
When I use the regular login module, however, it just creates the user as a Registered user, not as an Administrator. I'm not sure why the group map isn't working. As best as I can tell, I've set it up exactly as described in the documentation. What am I missing?