diff --git a/src/main/resources/serviceconfig/olat.properties b/src/main/resources/serviceconfig/olat.properties
index 1ddad16c806fe1b83e8c3e34b4e1d469038f4ed2..744de9513560d13b4dcbe708d68b81c26d64259f 100644
--- a/src/main/resources/serviceconfig/olat.properties
+++ b/src/main/resources/serviceconfig/olat.properties
@@ -935,7 +935,8 @@ ldap.attributename.useridentifyer=sAMAccountName
 ldap.attributename.email=mail
 ldap.attributename.firstName=givenName
 ldap.attributename.lastName=sn
-# attribute used as username to log in
+# Attribute used as username to log in. Note: the configured login attribute MUST be one of the mapped attributes below, e.g. genericTextProperty1 
+# If the login attribute should not be visible in OO, then disable the OO user property in all contexts. 
 ldap.login.attribute=${ldap.attributename.useridentifyer}
 #mappings from ldap-attrib to olat-userproperty
 ldap.attrib.gen.map.ldapkey1=