Note to myself to remember:

If I delete/change/add Active Directory Domains in I need to make sure that in REALMS the changes are reflected.

Otherwise an authentication attempt using wpa_supplicant -c /etc/wpa_supplicant/packetfence-demo.conf -D wired -i ens192 might end with EAP-TLV: TLV Result - Failure.