The ad_compat option has been backported to cyrus-sasl package from upstream.
This option helps users of the cyrus-sasl library (such as SSSD) in scenerios where SASL signing is requires by an Active Directory server. Without the ad_compat option, clients were unable to establish connection to AD servers which require SASL signing. Please refer to https://support.microsoft.com/kb/935834 for more information on the Active Directory setup details.
The ad_compat client side SASL option was backported from upstream. It controls compatibility with AD or similar servers that require both integrity and confidentiality bits selected during security layer negotiation.