Colleagues, we are trying to map group membership to users' multi-value attribute, but it does not as expected. If we set up Active Directory Account Template mapping directly in LDAP, the account template only maps the first value of the multi-value attribute. The user console or provisioning manager does not allow us to specify the mapping to the user attribute. The documentation of CA IM also does not seem to properly deswcribe this use-case.
Any help will be appreciated. Thank you!
I think mapping attributes in Account template is not best suited for AD Group membership addition/removal. You are best with using PX to handle this. Here is a post on how to use PX to assign AD group to a user:
@Make a user a member of Active Directory Group via Policy Xpress.. #assignadgroupspx