[Samba] ACL by LDAP port 389/636

Hello Samba Team,

We have AD controller with opened ldap ports (389/636).
Problem is that users can connect by application like Apache DIrectory Studio and they see all ldap tree.
Is it any solution to:
- block view for all users without specific ACL,
- block same attribute like uidNumber ?

I'm lokking something like ACL in OpenLdap for Samba AD.

Maybe somebody can help ?

Best regards,
Support 3eb

