Was testing today if
#FreeIPA can establish trust to Windows Server 2025-based Active Directory (it does work fine). And then tried to test if I can login with IPA user to that Windows Server 2025 domain controller without my global catalog code. Apparently, I can: it just takes ~2000 network packets as Windows is taking a happy way with Protected Storage interface and retries several hundred times to access it, all including initial reauthentication.