Thanks for the suggestions, but due to my inexperience in LDAP, these solutions seem to be too complicated for me. I'm thinking whether I should use hostObject to restrict access to ownCloud too. I tested, it is possible: I could easily add an LDAP filter in ownCloud to test for the "host" attribute. Maybe I will stick with that. However, I think I'm misusing the "host" attribute with this, as in my understanding it should be used for controlling shell-access, and not website-access. Is there a similar schema/attribute to control access to web services, or should I stick with hostObject?