Cause: SSSD would use either the value of dns_discovery_domain or else the hostname portion of the machine's FQDN to look up DNS SRV records for failover servers.
Consequence: On FreeIPA-enrolled machines, the client hostname might not match the IPA domain name. These clients would be unable to discover failover servers.
Change: When id_provider = ipa, dns_discovery_domain will be automatically set to the value if ipa_domain.
Result: FreeIPA clients will be able to autodetect failover servers even if their hostname is not part of the FreeIPA domain.