So,here comes the output from an actual try via radtest:
Mon Oct 3 21:16:24 2016 : Info: Ready to process requests.
rad_recv: Access-Request packet from host 127.0.0.1 port 39583, id=246, length=80
User-Name = "###username###"
User-Password = "###password###"
NAS-IP-Address = 127.0.1.1
NAS-Port = 1812
Message-Authenticator = 0xae07c03a0fa5825814f6e4066277a23b
Mon Oct 3 21:29:05 2016 : Info: # Executing section authorize from file /etc/freeradius/sites-enabled/default
Mon Oct 3 21:29:05 2016 : Info: +- entering group authorize {...}
Mon Oct 3 21:29:05 2016 : Info: ++[preprocess] returns ok
Mon Oct 3 21:29:05 2016 : Info: ++[chap] returns noop
Mon Oct 3 21:29:05 2016 : Info: ++[mschap] returns noop
Mon Oct 3 21:29:05 2016 : Info: [eap] No EAP-Message, not doing EAP
Mon Oct 3 21:29:05 2016 : Info: ++[eap] returns noop
Mon Oct 3 21:29:05 2016 : Info: [files] users: Matched entry DEFAULT at line 1
Mon Oct 3 21:29:05 2016 : Info: ++[files] returns ok
Mon Oct 3 21:29:05 2016 : Info: [ldap] performing user authorization for ###username###
Mon Oct 3 21:29:05 2016 : Info: [ldap] expand: %{Stripped-User-Name} ->
Mon Oct 3 21:29:05 2016 : Info: [ldap] ... expanding second conditional
Mon Oct 3 21:29:05 2016 : Info: [ldap] expand: %{User-Name} -> ###username###
Mon Oct 3 21:29:05 2016 : Info: [ldap] expand: (sAMAccountName=%{%{Stripped-User-Name}:-%{User-Name}}) -> (sAMAccountName=###username###)
Mon Oct 3 21:29:05 2016 : Info: [ldap] expand: DC=fritz,DC=box -> DC=fritz,DC=box
Mon Oct 3 21:29:05 2016 : Debug: [ldap] ldap_get_conn: Checking Id: 0
Mon Oct 3 21:29:05 2016 : Debug: [ldap] ldap_get_conn: Got Id: 0
Mon Oct 3 21:29:05 2016 : Debug: [ldap] attempting LDAP reconnection
Mon Oct 3 21:29:05 2016 : Debug: [ldap] (re)connect to ldap://127.0.0.1, authentication 0
Mon Oct 3 21:29:05 2016 : Debug: [ldap] bind as CN=zentyal-radius-zentyal,CN=Users,DC=fritz,DC=box/###password### to ldap://127.0.0.1
Mon Oct 3 21:29:05 2016 : Debug: [ldap] waiting for bind result ...
Mon Oct 3 21:29:05 2016 : Error: [ldap] LDAP login failed: check identity, password settings in ldap section of radiusd.conf
Mon Oct 3 21:29:05 2016 : Error: [ldap] (re)connection attempt failed
Mon Oct 3 21:29:05 2016 : Info: [ldap] search failed
Mon Oct 3 21:29:05 2016 : Debug: [ldap] ldap_release_conn: Release Id: 0
Mon Oct 3 21:29:05 2016 : Info: ++[ldap] returns fail
Mon Oct 3 21:29:05 2016 : Auth: Invalid user: [###username###] (from client 127.0.0.1/32 port 1812)
Mon Oct 3 21:29:05 2016 : Info: Using Post-Auth-Type Reject
Mon Oct 3 21:29:05 2016 : Info: # Executing group from file /etc/freeradius/sites-enabled/default
Mon Oct 3 21:29:05 2016 : Info: +- entering group REJECT {...}
Mon Oct 3 21:29:05 2016 : Info: [attr_filter.access_reject] expand: %{User-Name} -> ###username###
Mon Oct 3 21:29:05 2016 : Debug: attr_filter: Matched entry DEFAULT at line 11
Mon Oct 3 21:29:05 2016 : Info: ++[attr_filter.access_reject] returns updated
Mon Oct 3 21:29:05 2016 : Info: Delaying reject of request 0 for 1 seconds
Mon Oct 3 21:29:05 2016 : Debug: Going to the next request
Mon Oct 3 21:29:05 2016 : Debug: Waking up in 0.9 seconds.
Mon Oct 3 21:29:06 2016 : Info: Sending delayed reject for request 0
Sending Access-Reject of id 246 to 127.0.0.1 port 39583
Mon Oct 3 21:29:06 2016 : Debug: Waking up in 4.9 seconds.
Mon Oct 3 21:29:11 2016 : Info: Cleaning up request 0 ID 246 with timestamp +761
Mon Oct 3 21:29:11 2016 : Info: Ready to process requests.
User Info is also accessible:
User info (Level-0):
====================
Name: zentyal-radius-zentyal
SID: S-1-5-21-1293354772-482189516-68840057-1231
Uid: 910689487
Gid: 910688769
Gecos: <null>
Shell: /bin/sh
Home dir: /home/local/FRITZ/zentyal-radius-zentyal
Logon restriction: NO