You will need the authentication to go to local after LDAP the options are not pretty.
Kill the network access path from the firewall to LDAP so it won't get a response and proceed to local
temporarily remove the ISG from LDAP
Temporarily disable LDAP in the configuration
Delete the user from LDAP