For Active Directory we need: OCIS_LDAP_DISABLE_USER_MECHANISM=none. Until we add support for evaluating the "userAccountControl" bitmask, we don't supported display the account enable/disable state for Active Directory users.