Hi,
the attached patches implement the new option ad_access_control as designed in https://fedorahosted.org/sssd/wiki/DesignDocs/ActiveDirectoryAccessControl
The only part not implemented exactly as per the design page is changing the default. I will write an e-mail about the issue into the thread with the design decision so that also people who filter out patches can participate.