MODIFIED DEFAULT OPTIONS
Certain option defaults do not match their respective backend
provider defaults, these option names and AD provider-specific
defaults are listed below:
KRB5 Provider
krb5_validate = true
krb5_use_enterprise_principal = true
LDAP Provider
ldap_schema = ad
ldap_force_upper_case_realm = true
ldap_id_mapping = true
ldap_sasl_mech = gssapi
ldap_referrals = false
ldap_account_expire_policy = ad
ldap_use_tokengroups = true