I see in WSS v3 that when I am adding users to anything I get the
chance to search and it can find users in the domain. This is great.
However what I need is to restrict the scope of that search, so that
for everything under Top-Level-Site-A it only searches for user
accounts under the TLSA Organizational Unit, and for Top-Level-Site-B
it only searches for user accounts under the TLSB OU.

Is this possible? Are there any hooks to programatically handle the
user directory search?

-John