Assigning default role(s) to new users

Yes that is correct.
There may be other AD/DB connections that belong to CUSTOMERS, only one specific AD connection for INTERNAL users.