"What I want is a routine that can be called to search the AD directory, and return a mapping for all users with their groups (or vise versa)."
This is not a Net::LDAP solution, however you may wish to have a look at the source code from the Active Directory Cookbook. If you use it, you could buy a copy and do the author a favor :)