The `ad` identity mapper backend is apparently the only one that can use shell, home directory, etc. attributes from the directory now (as of Samba 4.6).
The *winbind* role builds upon the *samba* role to configure the machine as an Active Directory domain member.