Oh - you might be on to something here! On v15 it presents the domain name twice as well, in the first instance. Then it binds as 'svc LDAP', successfully. It then performs an LDAP Search Request on my 'mail' attribute.
That returns my account, with a mass of 85 attributes.
It then searches for '<ROOT>', scope baseObject, class *, which is apparently successful, though the matchedDN is blank.
That's where they diverge. v16 unbinds from LDAP, whereas v15... Wow - v15 requests every attribute available in the AD and gets about 1470 packets dumped in its lap... v15 then binds to my user, authenticates, and finishes.
I had to increase the buffer size for the packet capture for this beast. Right - it's going to take me a lot more concentration than I'll be mustering at this time of day. I'm going to try to look through this with a clear head in the morning, but it appears to me that v16 is not receiving something that it expects, whereas v15 is happy to push on and demand 1.8MB of attributes in order to login. :-/
Thanks - I'll update this once I've had a good scour at the packet capture.