I think this is the part where I get a little mixed up.
If using master-backup master (no locals) configuration and ultimately using HA, then what IP is passed to the APs as the standby controller.
For the example configuration below (for my lab environment)
interface vlan 1
ip address 10.3.1.99 255.255.255.0
master-redundancy
master-vrrp 1
peer-ip-address 10.3.1.249 ipsec 38abf8a843e037c768d137a778b65eed67f6cf96dc6903b6
vrrp 1
priority 110
ip address 10.3.1.250
vlan 1
no shutdown
ha group-profile "HA Group 1"
preemption
state-sync
pre-shared-key b5ea51fbaaeee697dc7e290426df8eb71d601534bac85c53
controller 10.3.1.249 role standby
controller 10.3.1.99 role active
Essentially I would provide the LMS IP for an AP group as the 10.3.1.99 address, and it will provide 10.3.1.249 as the standby controller. Totally ignoring the VRRP address of 10.3.1.250.
Limited lab, so I'm not sure if I can actually produce a failover situation to see if this works. I'm looking to see what configuration the AP received.