The purpose is to allow users access by ldap criteria like group so the sodoers file need not be edited on each and every server.

https://www.sudo.ws/docs/man/sudoers.ldap.man/

Yeah, that’s not something I would expect a core until to do.

I would expect another system to query ldap.