It would be great to have the option of disabling local authentication unless AD/LDAP authentication fails. In some cases AD/LDAP is strongly preferred over local authenticatio. In cases where Orion is unable to authenticate with AD local authentication could be enabled by the admin account.