The current design places control of Active Directory authentication in the hands of the end user, which is contrary to standard enterprise identity management practices.
In most enterprise applications, Active Directory integration is administered centrally, with administrators determining whether a user authenticates via Active Directory or via a local application account.
Once Active Directory authentication is enabled for a user, it should be enforced and not configurable by the user themselves. This ensures password policies, account disablement, security controls, and identity governance remain under IT administration.
We would recommend the platform support:
Global enablement of Active Directory authentication by administrators.
Administrative control over which users authenticate via AD versus local authentication.
The ability to lock authentication methods so users cannot modify them.
Retention of one or more emergency "break-glass" administrator accounts that use local authentication in the event AD services become unavailable.
This model aligns with the authentication approach used across most enterprise applications and identity management platforms