ugh why can't microsoft just let me rawdog LDAP instead of having to run an on-prem AD server