mod_shared_roster_ldap: users see/get only shared rosters they are member of

It can be a question with an obvious answer, but:

How can I restrict what shared rosters a user get? With my current config (below), all users see/get all rosters, and not only one they are member of (what I expected) - its like I'm missing something simple in the config: someone can help-me?

===== relevant part of my ejabberd.yml =====

  mod_shared_roster_ldap:
    ldap_user_cache_validity: 7200
    ldap_group_cache_validity: 7200
    ldap_groupattr: "department"
    ldap_rfilter: "(mail=*)"
    ldap_memberattr: "sAMAccountName"
    ldap_userdesc: "displayName"

=====

enable module mod_admin_extra

enable module mod_admin_extra :{} in ejabberd.yml. Commnad "get roster user server" will give only list of rosters of user.

Syndicate content