Alexander, thank you very much for your config sample, I took some time and compared to mine and they're pretty much the same, I want to move mailboxes to Maildir style because the system I'm planning to migrate to this IPA deployment does use Maildir style mailboxes.
I would still suggest you to check if plain IPA setup is working, i.e.
if you can successfuly use GSSAPI against Dovecot from a Linux client
with Thunderbird or mutt.

Once that is working, you can be sure that your server side is in order
and start looking at how to integrate Windows machines.

