MODIFIED DEFAULT OPTIONS Certain option defaults do not match their respective backend provider defaults, these option names and AD provider-specific defaults are listed below: KRB5 Provider krb5_validate = true krb5_use_enterprise_principal = true LDAP Provider ldap_schema = ad ldap_force_upper_case_realm = true ldap_id_mapping = true ldap_sasl_mech = gssapi ldap_referrals = false ldap_account_expire_policy = ad ldap_use_tokengroups = true