So the users would be able to log In for the Cache Time Period that is set up in the individual LDAP connection. The issue would be I don't think they would just auto "convert" to local accounts for password reset the user would not be able to log in until the next sync with AD. You would likely be recreating all of the user accounts, and since there is not a supported template import from csv for users it would be by hand. If there are a lot of users good luck to you. You would also likely lose the clients ticket history.
My question would be how is this a multiple authentication platform? You are using the same credentials as AD so its all one platform. If you mean that the users get prompted a second time for autntentication would it not be easier to set up SSO?