For backwards compatibility reasons, the LDAP plugin will create a role ROLE_FOO for every role/group Foo of a user by default. If you're not using these ROLE_* roles in your security configuration and don't want this duplication of roles, you can check this option so they'll no longer be created.