You could also narrow you ldap search to only look at groups that are related to CheckMK logins. That way you will only get changes when a user is actually added/removed to/from a group in LDAP that applys to CheckMK login.
My guess is that you are looking at the top of you tree?