On such a domain, sign-in sync creates no account (the person gets an ordinary authentication failure), changes nothing on an existing one, and creates no group from a groups claim. Without the flag sync works as before, and turning it off hands accounts back to sync with no restart. Checked through synchronize_account itself; acceptance test 5 does the same over OIDC once per-domain directories exist.