Today, the default role is always anonymous. It would be good to allow users to cofnigure the default role which is used when users come in from LDAP.
This came out of a discussions around https://bugzilla.redhat.com/show_bug.cgi?id=997046
Created redmine issue http://projects.theforeman.org/issues/7048 from this bug
Closing based on upstream comments <SNIP> The way this is meant to work is that you assign the role to a user group, then configure the user group via external user groups to sync with one of your LDAP groups (same works for Kerberos/REMOTE_USER type integration). Given that you can assign roles to groups, it doesn't make much sense to try and force roles into LDAP. </SNIP>