It's been a while but it depends on how your forest and such is setup in AD. look at the contents of memberOf, CN, and SN.
the member of is the full OU, for example one of my filters reads:
!(memberOf=CN=MyDomain Do Not Display,CN=Users,DC=MyDomain,DC=net)
Vegans are friends, not food...