Hello,

I tried something similar some time ago. If I remember it correctly, there is a configuration key that reverses the way openstack interprets the enabled field.

Looking at a part of https://docs.openstack.org/admin-guide/identity-integrate-with-ldap.html

 [ldap]
user_id_attribute      = cn
user_name_attribute    = sn
user_mail_attribute    = mail
user_enabled_attribute = userAccountControl
user_enabled_invert    = false
user_enabled_default   = 512
user_default_project_id_attribute =