Hi emilyforcisco1,
The article is fine, at the end is not really necessary to do the mapping via the OU since you can actually select some other attributes, the specific steps for this on that article will be the "Create the Certificate to Profile Map".
You can also take a look to this Cisco documentation:
http://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/116111-11611-config-double-authen-00.html#anc16
You can ignore the AAA configuration and focus on the certificate mapping steps.
Hope this info helps!!
Rate if helps you!!
-JP-