I made a proposal for a different approach to LDAP/Active Directory integration for kratos - make the LDAP client external, accessed via a REST API, similar to how oathkeeper works.
a little more detail here:
https://github.com/ory/kratos/issues/274
I am interested in what the Ory folks think of this.