Cause: SSSD versions prior to 1.9 would typically use id_provider=ldap when connecting to Active Directory. That configuration required quite some tweaking and couldn't use the advanced features that are AD specific.
Consequence: Configuring the SSSD as an AD client required AD knowledge and the performance was not optimal
Change: A new provider for the SSSD was implemented
Result: The administrator can set up AD client without having to know the specific AD attribute mappings and performance of AD provider is better especially during login than performance of LDAP provider.