Selecting users and groups from LDAP Server

We are running PAM 4.1 and are looking into upgrading from the Command Control policy engine to the Access Control policy engine. When creating a user role, if we drill down into our LDAP server to add a user/group, we get the following, with the three dots animating but minutes pass without anything being displayed. We do have many users/groups in eDir but how long do we need to wait until entries start appearing? Our users OU has ~400k entries and we have the Base DN of the eDir LDAP Server set to the user OU.