Normally user should be created from the UI of cluster-admin. Probably you have missed a mandatory setting
It is completely fine to create users from the cluster-admin UI.
But I don’t want customers to log in to the cluster-admin UI, so I tested Lam.
Is the mandatory setting a forced password change? It cannot be used even after it is checked.
Ldap users are not able to login to the cluster admin…afaik
The Core provides the User Management Portal. It is an UI separate from cluster admin where LDAP-defined users can change their passwords (even after expiration) and members of Domain Admins group can create and manage users and groups of the domain. See also User domains — NS8 documentation
If you still want to use LAM, do not forget to set the displayName LDAP attribute. At least Nextcloud seems to require it to accept the user login.