IDM changes the AD account password when a user account is moved between OUs in AD.

Hello,

We have identified an issue with IDM to AD synchronization in our environment, where IDM changes the AD user account password when a user account is moved between OUs in AD. Is there a way to prevent IDM from triggering a password reset activity on the AD side when user accounts are moved or changed within AD OUs?

Labels:

Identity Manager
  • Verified Answer

    +1  

    On a move, IDM Sees a <sync> event. This is converted to an add or modify (if the object is associated modify, if not add) then on an add, tries to match.

    It uses the fiilter to decide what to send. nspmDistributionFilter should be in the filter as Sub-Notify, not sync.

    What do you have in your filter for nspmDistributionPasword?

  • 0 in reply to   

    Thank you for the reply. The current filter setting is sync for nspmDistributionPasword.

  • 0   in reply to 

    If you want a detailed explanation of why it is Sub-Notify and not Sub-sync you can read my articles from:

     Password Transformation Rule Sets 


    Password Transformation Rules in the Publisher Channel 

    Then you can see how that all can be applied to a really interesting use that we actually used at a client.


    Password Tunneling Model in Identity Manager

    Wrote these like 15 years ago now, still good and relevant.

  • 0 in reply to   

    Thank you for the additional details you provided regarding this matter.

  • 0 in reply to 

    We have made the mentioned changes on AD driver, but still IDM resetting the password when the user account is moved between OUs in AD.

  • 0   in reply to 

    Can you isolate a move event in trace and show us here?  (If you do paste it into the editor, please use the Insert button at the bottom, and select Code.  Paste into the code window.)  Lets see why this is happening.

  • 0 in reply to   

    DirXML Log Event -------------------
         Driver:   \IDM_TREE\system\driverset1\Active Directory Driver
         Channel:  Publisher
         Status:   Success
    [01/30/25 19:46:45.518]:Active Directory Driver PT:  Direct command from policy result
    [01/30/25 19:46:45.518]:Active Directory Driver PT:  
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##194b26bee52##0" level="success"><application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn></object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [01/30/25 19:46:45.521]:Active Directory Driver PT:  Applying to rename #2.
    [01/30/25 19:46:45.521]:Active Directory Driver PT:    Evaluating selection criteria for rule 'break if not a move or rename'.
    [01/30/25 19:46:45.522]:Active Directory Driver PT:      (if-operation not-match "move|rename") = FALSE.
    [01/30/25 19:46:45.522]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.523]:Active Directory Driver PT:    Evaluating selection criteria for rule 'setup for move validation'.
    [01/30/25 19:46:45.523]:Active Directory Driver PT:      (if-operation equal "move") = FALSE.
    [01/30/25 19:46:45.524]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.524]:Active Directory Driver PT:    Evaluating selection criteria for rule 'setup for rename validation'.
    [01/30/25 19:46:45.525]:Active Directory Driver PT:      (if-operation equal "rename") = TRUE.
    [01/30/25 19:46:45.525]:Active Directory Driver PT:    Rule selected.
    [01/30/25 19:46:45.525]:Active Directory Driver PT:    Applying rule 'setup for rename validation'.
    [01/30/25 19:46:45.526]:Active Directory Driver PT:      Action: do-set-local-variable("cached-object-value",token-parse-dn(start="-1",token-dest-attr("DirXML-ADContext"))).
    [01/30/25 19:46:45.527]:Active Directory Driver PT:        arg-string(token-parse-dn(start="-1",token-dest-attr("DirXML-ADContext")))
    [01/30/25 19:46:45.527]:Active Directory Driver PT:          token-parse-dn(start="-1",token-dest-attr("DirXML-ADContext"))
    [01/30/25 19:46:45.528]:Active Directory Driver PT:            token-parse-dn(start="-1",token-dest-attr("DirXML-ADContext"))
    [01/30/25 19:46:45.528]:Active Directory Driver PT:              token-dest-attr("DirXML-ADContext")
    [01/30/25 19:46:45.529]:Active Directory Driver PT:                Query from policy
    [01/30/25 19:46:45.529]:Active Directory Driver PT:                
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query class-name="user" scope="entry">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <read-attr attr-name="DirXML-ADContext"/>
        </query>
      </input>
    </nds>
    [01/30/25 19:46:45.531]:Active Directory Driver PT:                Pumping XDS to eDirectory.
    [01/30/25 19:46:45.532]:Active Directory Driver PT:                Performing operation query for .
    [01/30/25 19:46:45.533]:Active Directory Driver PT:                --JCLNT-- \IDM_TREE\system\driverset1\Active Directory Driver - Publisher : Duplicating : context = 742523169, tempContext = 742523151
    [01/30/25 19:46:45.534]:Active Directory Driver PT:                --JCLNT-- \IDM_TREE\system\driverset1\Active Directory Driver - Publisher : Calling free on tempContext = 742523151
    [01/30/25 19:46:45.535]:Active Directory Driver PT:                Query from policy result
    [01/30/25 19:46:45.536]:Active Directory Driver PT:                
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <instance class-name="User" event-id="0" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-NEW\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-NEW\SERVER_TEST" src-entry-id="34616">
          <association state="associated">f20e64655ece484da834bdda58c0d39a</association>
          <attr attr-name="DirXML-ADContext">
            <value timestamp="1738160205#2" type="string">CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM</value>
          </attr>
        </instance>
        <status event-id="0" level="success"></status>
      </output>
    </nds>
    [01/30/25 19:46:45.540]:Active Directory Driver PT:                Token Value: "CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM".
    [01/30/25 19:46:45.541]:Active Directory Driver PT:              Arg Value: "CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM".
    [01/30/25 19:46:45.541]:Active Directory Driver PT:            Token Value: "SERVER_TEST".
    [01/30/25 19:46:45.542]:Active Directory Driver PT:          Arg Value: "SERVER_TEST".
    [01/30/25 19:46:45.542]:Active Directory Driver PT:      Action: do-set-local-variable("current-object-value",token-src-dn(convert="true",start="-1")).
    [01/30/25 19:46:45.543]:Active Directory Driver PT:        arg-string(token-src-dn(convert="true",start="-1"))
    [01/30/25 19:46:45.543]:Active Directory Driver PT:          token-src-dn(convert="true",start="-1")
    [01/30/25 19:46:45.544]:Active Directory Driver PT:            Token Value: "SERVER_TEST".
    [01/30/25 19:46:45.544]:Active Directory Driver PT:          Arg Value: "SERVER_TEST".
    [01/30/25 19:46:45.545]:Active Directory Driver PT:    Evaluating selection criteria for rule 'move or rename validation'.
    [01/30/25 19:46:45.545]:Active Directory Driver PT:      (if-local-variable 'cached-object-value' match ".*") = TRUE.
    [01/30/25 19:46:45.546]:Active Directory Driver PT:      Expanded variable reference '$current-object-value$' to 'SERVER_TEST'.
    [01/30/25 19:46:45.547]:Active Directory Driver PT:      (if-local-variable 'cached-object-value' equal "$current-object-value$") = TRUE.
    [01/30/25 19:46:45.547]:Active Directory Driver PT:    Rule selected.
    [01/30/25 19:46:45.548]:Active Directory Driver PT:    Applying rule 'move or rename validation'.
    [01/30/25 19:46:45.548]:Active Directory Driver PT:      Action: do-veto().
    [01/30/25 19:46:45.548]:Active Directory Driver PT:Policy returned:
    [01/30/25 19:46:45.549]:Active Directory Driver PT:
    <nds dtdversion="2.2">
      <source>
        <product build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <move class-name="user" event-id="Active Directory Driver##194b26bee52##0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <parent src-dn="OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
            <association>a8c8f7c1bd7b1f4da471420d51f79be7</association>
          </parent>
        </move>
      </input>
    </nds>
    [01/30/25 19:46:45.553]:Active Directory Driver PT:Applying publisher filter.
    [01/30/25 19:46:45.553]:Active Directory Driver PT:Publisher processing move for CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM.
    [01/30/25 19:46:45.554]:Active Directory Driver PT:Applying command transformation policies.
    [01/30/25 19:46:45.554]:Active Directory Driver PT:Applying policy: %+C%14CNOVLADDCFG-pub-ctp-UserNameMap%-C.
    [01/30/25 19:46:45.555]:Active Directory Driver PT:  Applying to move #1.
    [01/30/25 19:46:45.555]:Active Directory Driver PT:    Evaluating selection criteria for rule 'consider user objects when name mapping is enabled'.
    [01/30/25 19:46:45.556]:Active Directory Driver PT:      (if-class-name not-equal "User") = FALSE.
    [01/30/25 19:46:45.557]:Active Directory Driver PT:      (if-global-variable 'FullNameMap' equal "false") = FALSE.
    [01/30/25 19:46:45.557]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.557]:Active Directory Driver PT:    Evaluating selection criteria for rule 'full name mapping: discard unwanted renames'.
    [01/30/25 19:46:45.558]:Active Directory Driver PT:      (if-global-variable 'FullNameMap' equal "true") = TRUE.
    [01/30/25 19:46:45.559]:Active Directory Driver PT:      (if-operation equal "rename") = FALSE.
    [01/30/25 19:46:45.559]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.559]:Active Directory Driver PT:    Evaluating selection criteria for rule 'logon name mapping: map NT logon name to Identity Vault object name'.
    [01/30/25 19:46:45.560]:Active Directory Driver PT:      (if-global-variable 'LogonNameMap' equal "true") = TRUE.
    [01/30/25 19:46:45.561]:Active Directory Driver PT:      (if-operation equal "modify") = FALSE.
    [01/30/25 19:46:45.561]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.561]:Active Directory Driver PT:    Evaluating selection criteria for rule 'map e-mail address to Active Directory logon name'.
    [01/30/25 19:46:45.562]:Active Directory Driver PT:      (if-global-variable 'UpnMap' equal "ad-mail-auth") = FALSE.
    [01/30/25 19:46:45.563]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.563]:Active Directory Driver PT:    Evaluating selection criteria for rule 'unmap e-mail address from Active Directory logon name'.
    [01/30/25 19:46:45.564]:Active Directory Driver PT:      (if-global-variable 'UpnMap' equal "ad-mail-auth") = FALSE.
    [01/30/25 19:46:45.564]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.565]:Active Directory Driver PT:Policy returned:
    [01/30/25 19:46:45.565]:Active Directory Driver PT:
    <nds dtdversion="2.2">
      <source>
        <product build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <move class-name="User" dest-dn="data\users\SYSTEMD-NEW\SERVER_TEST" dest-entry-id="34616" event-id="Active Directory Driver##194b26bee52##0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <parent src-dn="OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
            <association>a8c8f7c1bd7b1f4da471420d51f79be7</association>
          </parent>
        </move>
      </input>
    </nds>
    [01/30/25 19:46:45.569]:Active Directory Driver PT:Applying policy: %+C%14CNOVLPWDSYNC-pub-cp-DefaultPwd%-C.
    [01/30/25 19:46:45.569]:Active Directory Driver PT:  Applying to move #1.
    [01/30/25 19:46:45.570]:Active Directory Driver PT:Policy returned:
    [01/30/25 19:46:45.570]:Active Directory Driver PT:
    <nds dtdversion="2.2">
      <source>
        <product build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <move class-name="User" dest-dn="data\users\SYSTEMD-NEW\SERVER_TEST" dest-entry-id="34616" event-id="Active Directory Driver##194b26bee52##0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <parent src-dn="OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
            <association>a8c8f7c1bd7b1f4da471420d51f79be7</association>
          </parent>
        </move>
      </input>
    </nds>
    [01/30/25 19:46:45.574]:Active Directory Driver PT:Applying policy: %+C%14CNOVLPWDSYNC-pub-ctp-CheckPwdGCV%-C.
    [01/30/25 19:46:45.574]:Active Directory Driver PT:  Applying to move #1.
    [01/30/25 19:46:45.575]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Block publishing passwords to the Identity Vault when adding an object'.
    [01/30/25 19:46:45.575]:Active Directory Driver PT:      (if-global-variable 'enable-password-publish' equal "false") = FALSE.
    [01/30/25 19:46:45.576]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.576]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Block sending modify-password changes to the Identity Vault'.
    [01/30/25 19:46:45.577]:Active Directory Driver PT:      (if-global-variable 'enable-password-publish' equal "false") = FALSE.
    [01/30/25 19:46:45.578]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.578]:Active Directory Driver PT:Policy returned:
    [01/30/25 19:46:45.578]:Active Directory Driver PT:
    <nds dtdversion="2.2">
      <source>
        <product build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <move class-name="User" dest-dn="data\users\SYSTEMD-NEW\SERVER_TEST" dest-entry-id="34616" event-id="Active Directory Driver##194b26bee52##0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <parent src-dn="OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
            <association>a8c8f7c1bd7b1f4da471420d51f79be7</association>
          </parent>
        </move>
      </input>
    </nds>
    [01/30/25 19:46:45.582]:Active Directory Driver PT:Applying policy: %+C%14CNOVLPWDSYNC-pub-ctp-PublishDistPwd%-C.
    [01/30/25 19:46:45.583]:Active Directory Driver PT:  Applying to move #1.
    [01/30/25 19:46:45.583]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Add nspmDistributionAttribute attribute to add operation'.
    [01/30/25 19:46:45.584]:Active Directory Driver PT:      (if-global-variable 'publish-password-to-dp' equal "true") = FALSE.
    [01/30/25 19:46:45.585]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.585]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Change modify-password operations to a modify'.
    [01/30/25 19:46:45.585]:Active Directory Driver PT:      (if-global-variable 'publish-password-to-dp' equal "true") = FALSE.
    [01/30/25 19:46:45.586]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.586]:Active Directory Driver PT:Policy returned:
    [01/30/25 19:46:45.587]:Active Directory Driver PT:
    <nds dtdversion="2.2">
      <source>
        <product build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <move class-name="User" dest-dn="data\users\SYSTEMD-NEW\SERVER_TEST" dest-entry-id="34616" event-id="Active Directory Driver##194b26bee52##0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <parent src-dn="OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
            <association>a8c8f7c1bd7b1f4da471420d51f79be7</association>
          </parent>
        </move>
      </input>
    </nds>
    [01/30/25 19:46:45.591]:Active Directory Driver PT:Applying policy: %+C%14CNOVLPWDSYNC-pub-ctp-PublishNDSPwd%-C.
    [01/30/25 19:46:45.591]:Active Directory Driver PT:  Applying to move #1.
    [01/30/25 19:46:45.592]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Block publishing passwords to eDirectory password'.
    [01/30/25 19:46:45.592]:Active Directory Driver PT:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:45.593]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.593]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Block sending modify-password changes to the eDirectory password'.
    [01/30/25 19:46:45.594]:Active Directory Driver PT:      (if-operation equal "modify-password") = FALSE.
    [01/30/25 19:46:45.594]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.594]:Active Directory Driver PT:Policy returned:
    [01/30/25 19:46:45.595]:Active Directory Driver PT:
    <nds dtdversion="2.2">
      <source>
        <product build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <move class-name="User" dest-dn="data\users\SYSTEMD-NEW\SERVER_TEST" dest-entry-id="34616" event-id="Active Directory Driver##194b26bee52##0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <parent src-dn="OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
            <association>a8c8f7c1bd7b1f4da471420d51f79be7</association>
          </parent>
        </move>
      </input>
    </nds>
    [01/30/25 19:46:45.597]:Active Directory Driver PT:Applying policy: %+C%14CNOVLPWDSYNC-pub-ctp-AddPwdPayload%-C.
    [01/30/25 19:46:45.598]:Active Directory Driver PT:  Applying to move #1.
    [01/30/25 19:46:45.598]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Add operation-data element to password operations'.
    [01/30/25 19:46:45.599]:Active Directory Driver PT:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:45.599]:Active Directory Driver PT:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:45.599]:Active Directory Driver PT:      (if-operation equal "modify-password") = FALSE.
    [01/30/25 19:46:45.600]:Active Directory Driver PT:      (if-operation equal "modify") = FALSE.
    [01/30/25 19:46:45.600]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.600]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Add payload data to password operations'.
    [01/30/25 19:46:45.601]:Active Directory Driver PT:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:45.601]:Active Directory Driver PT:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:45.601]:Active Directory Driver PT:      (if-operation equal "modify-password") = FALSE.
    [01/30/25 19:46:45.602]:Active Directory Driver PT:      (if-operation equal "modify") = FALSE.
    [01/30/25 19:46:45.602]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.603]:Active Directory Driver PT:Policy returned:
    [01/30/25 19:46:45.603]:Active Directory Driver PT:
    <nds dtdversion="2.2">
      <source>
        <product build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <move class-name="User" dest-dn="data\users\SYSTEMD-NEW\SERVER_TEST" dest-entry-id="34616" event-id="Active Directory Driver##194b26bee52##0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <parent src-dn="OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
            <association>a8c8f7c1bd7b1f4da471420d51f79be7</association>
          </parent>
        </move>
      </input>
    </nds>
    [01/30/25 19:46:45.606]:Active Directory Driver PT:Applying policy: %+C%14CNOVLADDCFG-pub-ctp%-C.
    [01/30/25 19:46:45.606]:Active Directory Driver PT:  Applying to move #1.
    [01/30/25 19:46:45.606]:Active Directory Driver PT:    Evaluating selection criteria for rule 'set cached context value on merge'.
    [01/30/25 19:46:45.607]:Active Directory Driver PT:      (if-operation equal "modify") = FALSE.
    [01/30/25 19:46:45.607]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.607]:Active Directory Driver PT:    Evaluating selection criteria for rule 'remove managed attributes when object disassociated'.
    [01/30/25 19:46:45.608]:Active Directory Driver PT:      (if-operation equal "remove-association") = FALSE.
    [01/30/25 19:46:45.608]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.609]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Prevent unassociated users from being removed from groups'.
    [01/30/25 19:46:45.609]:Active Directory Driver PT:      (if-operation equal "modify") = FALSE.
    [01/30/25 19:46:45.609]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.610]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Set Equivalent To Me when group members change'.
    [01/30/25 19:46:45.610]:Active Directory Driver PT:      (if-class-name equal "Group") = FALSE.
    [01/30/25 19:46:45.611]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.611]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Set uniqueID if unavailable'.
    [01/30/25 19:46:45.611]:Active Directory Driver PT:      (if-class-name equal "User") = TRUE.
    [01/30/25 19:46:45.612]:Active Directory Driver PT:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:45.612]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:45.612]:Active Directory Driver PT:Policy returned:
    [01/30/25 19:46:45.612]:Active Directory Driver PT:
    <nds dtdversion="2.2">
      <source>
        <product build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <move class-name="User" dest-dn="data\users\SYSTEMD-NEW\SERVER_TEST" dest-entry-id="34616" event-id="Active Directory Driver##194b26bee52##0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <parent src-dn="OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
            <association>a8c8f7c1bd7b1f4da471420d51f79be7</association>
          </parent>
        </move>
      </input>
    </nds>
    [01/30/25 19:46:45.615]:Active Directory Driver PT:Applying XSLT policy: %+C%14CNOVLADDCFG-pub-cts%-C.
    [01/30/25 19:46:45.616]:Active Directory Driver PT:Policy returned:
    [01/30/25 19:46:45.616]:Active Directory Driver PT:
    <nds dtdversion="2.2">
      <source>
        <product build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <move class-name="User" dest-dn="data\users\SYSTEMD-NEW\SERVER_TEST" dest-entry-id="34616" event-id="Active Directory Driver##194b26bee52##0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <parent src-dn="OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
            <association>a8c8f7c1bd7b1f4da471420d51f79be7</association>
          </parent>
        </move>
      </input>
    </nds>
    [01/30/25 19:46:45.619]:Active Directory Driver PT:Filtering out notification-only attributes.
    [01/30/25 19:46:45.619]:Active Directory Driver PT:Pumping XDS to eDirectory.
    [01/30/25 19:46:45.620]:Active Directory Driver PT:Performing operation move for data\users\SYSTEMD-NEW\SERVER_TEST.
    [01/30/25 19:46:45.621]:Active Directory Driver PT:--JCLNT-- \IDM_TREE\system\driverset1\Active Directory Driver - Publisher : Duplicating : context = 742523169, tempContext = 742523151
    [01/30/25 19:46:45.654]:Active Directory Driver PT:Waiting to move entry \IDM_TREE\data\users\SYSTEMD-NEW\SERVER_TEST until local changes are synced to master replica.
    [01/30/25 19:46:46.662]:Active Directory Driver PT:Waiting to move entry \IDM_TREE\data\users\SYSTEMD-NEW\SERVER_TEST until local changes are synced to master replica.
    [01/30/25 19:46:47.666]:Active Directory Driver PT:Waiting to move entry \IDM_TREE\data\users\SYSTEMD-NEW\SERVER_TEST until local changes are synced to master replica.
    [01/30/25 19:46:48.673]:Active Directory Driver PT:Moving entry \IDM_TREE\data\users\SYSTEMD-NEW\SERVER_TEST to \IDM_TREE\data\users\SYSTEMD-OLD.
    [01/30/25 19:46:48.690]:Active Directory Driver PT:Waiting for moved object \IDM_TREE\data\users\SYSTEMD-OLD to replicate from master replica.
    [01/30/25 19:46:50.692]:Active Directory Driver PT:Waiting for moved object \IDM_TREE\data\users\SYSTEMD-OLD to replicate from master replica.
    [01/30/25 19:46:50.717]:Active Directory Driver ST:Start transaction.
    [01/30/25 19:46:50.718]:Active Directory Driver ST:type(move-entry)entry-id(34616) dn(\T=IDM_TREE\O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST) class-id(441) class-name(User)
    [01/30/25 19:46:50.719]:Active Directory Driver ST:Processing events for transaction.
    [01/30/25 19:46:50.720]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <sync cached-time="20250129141650.701Z" class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-move="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616" timestamp="0#0">
          <association state="associated">f20e64655ece484da834bdda58c0d39a</association>
        </sync>
        <move cached-time="20250129141650.701Z" class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" old-src-dn="\IDM_TREE\data\users\SYSTEMD-NEW\SERVER_TEST" qualified-old-src-dn="O=data\OU=users\OU=SYSTEMD-NEW\CN=SERVER_TEST" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616" timestamp="1738158684#8">
          <association state="associated">f20e64655ece484da834bdda58c0d39a</association>
          <parent qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD" src-entry-id="36157">
            <association>a8c8f7c1bd7b1f4da471420d51f79be7</association>
          </parent>
        </move>
      </input>
    </nds>
    [01/30/25 19:46:50.728]:Active Directory Driver ST:Applying event transformation policies.
    [01/30/25 19:46:50.728]:Active Directory Driver ST:Applying policy: %+C%14Cunlock1%-C.
    [01/30/25 19:46:50.729]:Active Directory Driver ST:  Applying to sync #1.
    [01/30/25 19:46:50.729]:Active Directory Driver ST:    Evaluating selection criteria for rule 'unlock'.
    [01/30/25 19:46:50.730]:Active Directory Driver ST:      (if-op-attr 'nspmDistributionPassword' changing) = FALSE.
    [01/30/25 19:46:50.730]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.731]:Active Directory Driver ST:  Applying to move #2.
    [01/30/25 19:46:50.731]:Active Directory Driver ST:    Evaluating selection criteria for rule 'unlock'.
    [01/30/25 19:46:50.732]:Active Directory Driver ST:      (if-op-attr 'nspmDistributionPassword' changing) = FALSE.
    [01/30/25 19:46:50.732]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.732]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.733]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <sync cached-time="20250129141650.701Z" class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-move="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616" timestamp="0#0">
          <association state="associated">f20e64655ece484da834bdda58c0d39a</association>
        </sync>
        <move cached-time="20250129141650.701Z" class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" old-src-dn="\IDM_TREE\data\users\SYSTEMD-NEW\SERVER_TEST" qualified-old-src-dn="O=data\OU=users\OU=SYSTEMD-NEW\CN=SERVER_TEST" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616" timestamp="1738158684#8">
          <association state="associated">f20e64655ece484da834bdda58c0d39a</association>
          <parent qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD" src-entry-id="36157">
            <association>a8c8f7c1bd7b1f4da471420d51f79be7</association>
          </parent>
        </move>
      </input>
    </nds>
    [01/30/25 19:46:50.743]:Active Directory Driver ST:Subscriber processing sync for \IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST.
    [01/30/25 19:46:50.744]:Active Directory Driver ST:Merging eDirectory and application values.
    [01/30/25 19:46:50.744]:Active Directory Driver ST:Reading relevant attributes from \IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST.
    [01/30/25 19:46:50.744]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query class-name="User" dest-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" dest-entry-id="34616" scope="entry">
          <read-attr attr-name="Description"/>
          <read-attr attr-name="Facsimile Telephone Number"/>
          <read-attr attr-name="Full Name"/>
          <read-attr attr-name="Given Name"/>
          <read-attr attr-name="Initials"/>
          <read-attr attr-name="Internet EMail Address"/>
          <read-attr attr-name="L"/>
          <read-attr attr-name="Login Allowed Time Map"/>
          <read-attr attr-name="Login Disabled"/>
          <read-attr attr-name="Login Expiration Time"/>
          <read-attr attr-name="Physical Delivery Office Name"/>
          <read-attr attr-name="Postal Code"/>
          <read-attr attr-name="Postal Office Box"/>
          <read-attr attr-name="S"/>
          <read-attr attr-name="SA"/>
          <read-attr attr-name="Surname"/>
          <read-attr attr-name="Telephone Number"/>
          <read-attr attr-name="Title"/>
        </query>
      </input>
    </nds>
    [01/30/25 19:46:50.749]:Active Directory Driver ST:Pumping XDS to eDirectory.
    [01/30/25 19:46:50.749]:Active Directory Driver ST:Performing operation query for \IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST.
    [01/30/25 19:46:50.750]:Active Directory Driver ST:--JCLNT-- \IDM_TREE\system\driverset1\Active Directory Driver : Duplicating : context = 742523075, tempContext = 742523186
    [01/30/25 19:46:50.751]:Active Directory Driver ST:--JCLNT-- \IDM_TREE\system\driverset1\Active Directory Driver : Calling free on tempContext = 742523186
    [01/30/25 19:46:50.751]:Active Directory Driver ST:Read result:
    [01/30/25 19:46:50.751]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <instance class-name="User" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association state="associated">f20e64655ece484da834bdda58c0d39a</association>
          <attr attr-name="Full Name">
            <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
          </attr>
          <attr attr-name="Given Name">
            <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
          </attr>
          <attr attr-name="Login Allowed Time Map">
            <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
          </attr>
          <attr attr-name="Login Disabled">
            <value timestamp="1738160208#28" type="state">false</value>
          </attr>
          <attr attr-name="Login Expiration Time">
            <value timestamp="1738160208#29" type="time">-1</value>
          </attr>
          <attr attr-name="Surname">
            <value timestamp="1738160208#45" type="string">UNKNOWN</value>
          </attr>
        </instance>
        <status level="success"></status>
      </output>
    </nds>
    [01/30/25 19:46:50.756]:Active Directory Driver ST:Reading relevant attributes from f20e64655ece484da834bdda58c0d39a.
    [01/30/25 19:46:50.757]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query class-name="User" scope="entry">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <read-attr attr-name="Description"/>
          <read-attr attr-name="DirXML-ADAliasName"/>
          <read-attr attr-name="Facsimile Telephone Number"/>
          <read-attr attr-name="Full Name"/>
          <read-attr attr-name="Given Name"/>
          <read-attr attr-name="Initials"/>
          <read-attr attr-name="Internet EMail Address"/>
          <read-attr attr-name="L"/>
          <read-attr attr-name="Login Allowed Time Map"/>
          <read-attr attr-name="Login Disabled"/>
          <read-attr attr-name="Login Expiration Time"/>
          <read-attr attr-name="nspmDistributionPassword"/>
          <read-attr attr-name="Physical Delivery Office Name"/>
          <read-attr attr-name="Postal Code"/>
          <read-attr attr-name="Postal Office Box"/>
          <read-attr attr-name="S"/>
          <read-attr attr-name="SA"/>
          <read-attr attr-name="Surname"/>
          <read-attr attr-name="Telephone Number"/>
          <read-attr attr-name="Title"/>
          <read-attr attr-name="workforceID"/>
        </query>
      </input>
    </nds>
    [01/30/25 19:46:50.762]:Active Directory Driver ST:Fixing up association references.
    [01/30/25 19:46:50.762]:Active Directory Driver ST:Applying schema mapping policies to output.
    [01/30/25 19:46:50.763]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-smp%-C.
    [01/30/25 19:46:50.763]:Active Directory Driver ST:  No mapping for class-name 'User'.
    [01/30/25 19:46:50.764]:Active Directory Driver ST:Applying output transformation policies.
    [01/30/25 19:46:50.764]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-otp-FormatConversions%-C.
    [01/30/25 19:46:50.765]:Active Directory Driver ST:  Applying to query #1.
    [01/30/25 19:46:50.765]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
    [01/30/25 19:46:50.766]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:50.767]:Active Directory Driver ST:    Applying rule 'Street Address: Convert LF to CR-LF'.
    [01/30/25 19:46:50.767]:Active Directory Driver ST:      Action: do-set-local-variable("CR-LF",scope="policy",token-char(value="13")+token-char(value="10")).
    [01/30/25 19:46:50.768]:Active Directory Driver ST:        arg-string(token-char(value="13")+token-char(value="10"))
    [01/30/25 19:46:50.769]:Active Directory Driver ST:          token-char(value="13")
    [01/30/25 19:46:50.769]:Active Directory Driver ST:            Token Value: "
    ".
    [01/30/25 19:46:50.769]:Active Directory Driver ST:          token-char(value="10")
    [01/30/25 19:46:50.770]:Active Directory Driver ST:            Token Value: "
    ".
    [01/30/25 19:46:50.770]:Active Directory Driver ST:          Arg Value: "
    ".
    [01/30/25 19:46:50.771]:Active Directory Driver ST:      Action: do-reformat-op-attr("streetAddress",token-replace-all("(?<!\r)\n","$CR-LF$",token-local-variable("current-value"))).
    [01/30/25 19:46:50.771]:Active Directory Driver ST:    Evaluating selection criteria for rule 'logonHours: Convert to Active Directory form'.
    [01/30/25 19:46:50.772]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:50.772]:Active Directory Driver ST:    Applying rule 'logonHours: Convert to Active Directory form'.
    [01/30/25 19:46:50.773]:Active Directory Driver ST:      Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
    [01/30/25 19:46:50.774]:Active Directory Driver ST:    Evaluating selection criteria for rule 'accountExpires: Convert to Active Directory form'.
    [01/30/25 19:46:50.774]:Active Directory Driver ST:      (if-op-attr 'accountExpires' changing) = FALSE.
    [01/30/25 19:46:50.775]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.775]:Active Directory Driver ST:    Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
    [01/30/25 19:46:50.776]:Active Directory Driver ST:      (if-op-attr 'lockoutTime' available) = FALSE.
    [01/30/25 19:46:50.776]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.777]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
    [01/30/25 19:46:50.777]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:50.778]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.778]:Active Directory Driver ST:    Evaluating selection criteria for rule 'update Active Directory logon name'.
    [01/30/25 19:46:50.779]:Active Directory Driver ST:      (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
    [01/30/25 19:46:50.780]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.780]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.780]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query class-name="User" event-id="0" scope="entry">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <read-attr attr-name="Description"/>
          <read-attr attr-name="DirXML-ADAliasName"/>
          <read-attr attr-name="Facsimile Telephone Number"/>
          <read-attr attr-name="Full Name"/>
          <read-attr attr-name="Given Name"/>
          <read-attr attr-name="Initials"/>
          <read-attr attr-name="Internet EMail Address"/>
          <read-attr attr-name="L"/>
          <read-attr attr-name="Login Allowed Time Map"/>
          <read-attr attr-name="Login Disabled"/>
          <read-attr attr-name="Login Expiration Time"/>
          <read-attr attr-name="nspmDistributionPassword"/>
          <read-attr attr-name="Physical Delivery Office Name"/>
          <read-attr attr-name="Postal Code"/>
          <read-attr attr-name="Postal Office Box"/>
          <read-attr attr-name="S"/>
          <read-attr attr-name="SA"/>
          <read-attr attr-name="Surname"/>
          <read-attr attr-name="Telephone Number"/>
          <read-attr attr-name="Title"/>
          <read-attr attr-name="workforceID"/>
        </query>
      </input>
    </nds>
    [01/30/25 19:46:50.785]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-otp-ExchangeEntitlementQuery%-C.
    [01/30/25 19:46:50.785]:Active Directory Driver ST:  Applying to query #1.
    [01/30/25 19:46:50.786]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add dest-dn to the Exchange Entitlement Query'.
    [01/30/25 19:46:50.786]:Active Directory Driver ST:      (if-operation match "query|query-ex") = TRUE.
    [01/30/25 19:46:50.786]:Active Directory Driver ST:      (if-class-name equal "msExchPrivateMDB") = FALSE.
    [01/30/25 19:46:50.787]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.787]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.787]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query class-name="User" event-id="0" scope="entry">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <read-attr attr-name="Description"/>
          <read-attr attr-name="DirXML-ADAliasName"/>
          <read-attr attr-name="Facsimile Telephone Number"/>
          <read-attr attr-name="Full Name"/>
          <read-attr attr-name="Given Name"/>
          <read-attr attr-name="Initials"/>
          <read-attr attr-name="Internet EMail Address"/>
          <read-attr attr-name="L"/>
          <read-attr attr-name="Login Allowed Time Map"/>
          <read-attr attr-name="Login Disabled"/>
          <read-attr attr-name="Login Expiration Time"/>
          <read-attr attr-name="nspmDistributionPassword"/>
          <read-attr attr-name="Physical Delivery Office Name"/>
          <read-attr attr-name="Postal Code"/>
          <read-attr attr-name="Postal Office Box"/>
          <read-attr attr-name="S"/>
          <read-attr attr-name="SA"/>
          <read-attr attr-name="Surname"/>
          <read-attr attr-name="Telephone Number"/>
          <read-attr attr-name="Title"/>
          <read-attr attr-name="workforceID"/>
        </query>
      </input>
    </nds>
    [01/30/25 19:46:50.792]:Active Directory Driver ST:Applying policy: %+C%14CNOVLPWDSYNC-otp-EmailOnFailedPwdPub%-C.
    [01/30/25 19:46:50.792]:Active Directory Driver ST:  Applying to query #1.
    [01/30/25 19:46:50.793]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Send e-mail for a failed publish password operation'.
    [01/30/25 19:46:50.793]:Active Directory Driver ST:      (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
    [01/30/25 19:46:50.794]:Active Directory Driver ST:      (if-operation equal "status") = FALSE.
    [01/30/25 19:46:50.794]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.794]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.794]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query class-name="User" event-id="0" scope="entry">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <read-attr attr-name="Description"/>
          <read-attr attr-name="DirXML-ADAliasName"/>
          <read-attr attr-name="Facsimile Telephone Number"/>
          <read-attr attr-name="Full Name"/>
          <read-attr attr-name="Given Name"/>
          <read-attr attr-name="Initials"/>
          <read-attr attr-name="Internet EMail Address"/>
          <read-attr attr-name="L"/>
          <read-attr attr-name="Login Allowed Time Map"/>
          <read-attr attr-name="Login Disabled"/>
          <read-attr attr-name="Login Expiration Time"/>
          <read-attr attr-name="nspmDistributionPassword"/>
          <read-attr attr-name="Physical Delivery Office Name"/>
          <read-attr attr-name="Postal Code"/>
          <read-attr attr-name="Postal Office Box"/>
          <read-attr attr-name="S"/>
          <read-attr attr-name="SA"/>
          <read-attr attr-name="Surname"/>
          <read-attr attr-name="Telephone Number"/>
          <read-attr attr-name="Title"/>
          <read-attr attr-name="workforceID"/>
        </query>
      </input>
    </nds>
    [01/30/25 19:46:50.800]:Active Directory Driver ST:Submitting document to subscriber shim:
    [01/30/25 19:46:50.800]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query class-name="User" event-id="0" scope="entry">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <read-attr attr-name="Description"/>
          <read-attr attr-name="DirXML-ADAliasName"/>
          <read-attr attr-name="Facsimile Telephone Number"/>
          <read-attr attr-name="Full Name"/>
          <read-attr attr-name="Given Name"/>
          <read-attr attr-name="Initials"/>
          <read-attr attr-name="Internet EMail Address"/>
          <read-attr attr-name="L"/>
          <read-attr attr-name="Login Allowed Time Map"/>
          <read-attr attr-name="Login Disabled"/>
          <read-attr attr-name="Login Expiration Time"/>
          <read-attr attr-name="nspmDistributionPassword"/>
          <read-attr attr-name="Physical Delivery Office Name"/>
          <read-attr attr-name="Postal Code"/>
          <read-attr attr-name="Postal Office Box"/>
          <read-attr attr-name="S"/>
          <read-attr attr-name="SA"/>
          <read-attr attr-name="Surname"/>
          <read-attr attr-name="Telephone Number"/>
          <read-attr attr-name="Title"/>
          <read-attr attr-name="workforceID"/>
        </query>
      </input>
    </nds>
    [01/30/25 19:46:50.805]:Active Directory Driver ST:Remote Interface Driver: Sending...
    [01/30/25 19:46:50.805]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query class-name="User" event-id="0" scope="entry">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <read-attr attr-name="Description"/>
          <read-attr attr-name="DirXML-ADAliasName"/>
          <read-attr attr-name="Facsimile Telephone Number"/>
          <read-attr attr-name="Full Name"/>
          <read-attr attr-name="Given Name"/>
          <read-attr attr-name="Initials"/>
          <read-attr attr-name="Internet EMail Address"/>
          <read-attr attr-name="L"/>
          <read-attr attr-name="Login Allowed Time Map"/>
          <read-attr attr-name="Login Disabled"/>
          <read-attr attr-name="Login Expiration Time"/>
          <read-attr attr-name="nspmDistributionPassword"/>
          <read-attr attr-name="Physical Delivery Office Name"/>
          <read-attr attr-name="Postal Code"/>
          <read-attr attr-name="Postal Office Box"/>
          <read-attr attr-name="S"/>
          <read-attr attr-name="SA"/>
          <read-attr attr-name="Surname"/>
          <read-attr attr-name="Telephone Number"/>
          <read-attr attr-name="Title"/>
          <read-attr attr-name="workforceID"/>
        </query>
      </input>
    </nds>
    [01/30/25 19:46:50.810]:Active Directory Driver ST:Remote Interface Driver: Document sent.
    [01/30/25 19:46:50.811]:Active Directory Driver ST:Remote Interface Driver: Waiting for receive...
    [01/30/25 19:46:50.841]:Active Directory Driver ST:Remote Interface Driver: Received
    [01/30/25 19:46:50.842]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <instance class-name="user" event-id="0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
        </instance>
        <status event-id="0" level="success"/>
      </output>
    </nds>
    [01/30/25 19:46:50.845]:Active Directory Driver ST:Remote Interface Driver: Received command: SUBSCRIBER REPLY(10).
    [01/30/25 19:46:50.846]:Active Directory Driver ST:SubscriptionShim.execute() returned:
    [01/30/25 19:46:50.847]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <instance class-name="user" event-id="0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
        </instance>
        <status event-id="0" level="success"/>
      </output>
    </nds>
    [01/30/25 19:46:50.850]:Active Directory Driver ST:Applying input transformation policies.
    [01/30/25 19:46:50.850]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-itp-SubscriberUserAdd%-C.
    [01/30/25 19:46:50.851]:Active Directory Driver ST:  Applying to instance #1.
    [01/30/25 19:46:50.852]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Populate DirXML-ADContext on initial user add'.
    [01/30/25 19:46:50.853]:Active Directory Driver ST:      (if-operation equal "add-association") = FALSE.
    [01/30/25 19:46:50.856]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.856]:Active Directory Driver ST:  Applying to status #2.
    [01/30/25 19:46:50.857]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Populate DirXML-ADContext on initial user add'.
    [01/30/25 19:46:50.859]:Active Directory Driver ST:      (if-operation equal "add-association") = FALSE.
    [01/30/25 19:46:50.859]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.859]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.860]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <instance class-name="user" event-id="0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
        </instance>
        <status event-id="0" level="success"/>
      </output>
    </nds>
    [01/30/25 19:46:50.862]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-itp-FormatConversions%-C.
    [01/30/25 19:46:50.863]:Active Directory Driver ST:  Applying to instance #1.
    [01/30/25 19:46:50.863]:Active Directory Driver ST:    Evaluating selection criteria for rule 'streetAddress: Convert CR-LF to LF'.
    [01/30/25 19:46:50.864]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:50.864]:Active Directory Driver ST:    Applying rule 'streetAddress: Convert CR-LF to LF'.
    [01/30/25 19:46:50.865]:Active Directory Driver ST:      Action: do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
    [01/30/25 19:46:50.866]:Active Directory Driver ST:    Evaluating selection criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
    [01/30/25 19:46:50.867]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:50.867]:Active Directory Driver ST:    Applying rule 'logonHours: Convert to Login Allowed Time Map form'.
    [01/30/25 19:46:50.867]:Active Directory Driver ST:      Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
    [01/30/25 19:46:50.870]:Active Directory Driver ST:    Evaluating selection criteria for rule 'accountExpires: Convert to Identity Vault time format'.
    [01/30/25 19:46:50.872]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:50.872]:Active Directory Driver ST:    Applying rule 'accountExpires: Convert to Identity Vault time format'.
    [01/30/25 19:46:50.873]:Active Directory Driver ST:      Action: do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
    [01/30/25 19:46:50.874]:Active Directory Driver ST:    Evaluating selection criteria for rule 'lockedByIntruder: Enable Locked By Intruder'.
    [01/30/25 19:46:50.874]:Active Directory Driver ST:      (if-operation equal "modify") = FALSE.
    [01/30/25 19:46:50.877]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.877]:Active Directory Driver ST:    Evaluating selection criteria for rule 'lockedByIntruder: Disable Locked By Intruder'.
    [01/30/25 19:46:50.877]:Active Directory Driver ST:      (if-operation equal "modify") = FALSE.
    [01/30/25 19:46:50.878]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.878]:Active Directory Driver ST:    Evaluating selection criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
    [01/30/25 19:46:50.879]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:50.879]:Active Directory Driver ST:    Applying rule 'lockoutTime: Convert to Identity Vault time format'.
    [01/30/25 19:46:50.879]:Active Directory Driver ST:      Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
    [01/30/25 19:46:50.881]:Active Directory Driver ST:  Applying to status #2.
    [01/30/25 19:46:50.881]:Active Directory Driver ST:    Evaluating selection criteria for rule 'streetAddress: Convert CR-LF to LF'.
    [01/30/25 19:46:50.882]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:50.882]:Active Directory Driver ST:    Applying rule 'streetAddress: Convert CR-LF to LF'.
    [01/30/25 19:46:50.883]:Active Directory Driver ST:      Action: do-reformat-op-attr("streetAddress",token-replace-all("\r\n","\r",token-local-variable("current-value"))).
    [01/30/25 19:46:50.884]:Active Directory Driver ST:    Evaluating selection criteria for rule 'logonHours: Convert to Login Allowed Time Map form'.
    [01/30/25 19:46:50.884]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:50.885]:Active Directory Driver ST:    Applying rule 'logonHours: Convert to Login Allowed Time Map form'.
    [01/30/25 19:46:50.885]:Active Directory Driver ST:      Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2eDir($current-value)")).
    [01/30/25 19:46:50.886]:Active Directory Driver ST:    Evaluating selection criteria for rule 'accountExpires: Convert to Identity Vault time format'.
    [01/30/25 19:46:50.886]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:50.887]:Active Directory Driver ST:    Applying rule 'accountExpires: Convert to Identity Vault time format'.
    [01/30/25 19:46:50.887]:Active Directory Driver ST:      Action: do-reformat-op-attr("accountExpires",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
    [01/30/25 19:46:50.888]:Active Directory Driver ST:    Evaluating selection criteria for rule 'lockedByIntruder: Enable Locked By Intruder'.
    [01/30/25 19:46:50.889]:Active Directory Driver ST:      (if-operation equal "modify") = FALSE.
    [01/30/25 19:46:50.889]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.889]:Active Directory Driver ST:    Evaluating selection criteria for rule 'lockedByIntruder: Disable Locked By Intruder'.
    [01/30/25 19:46:50.890]:Active Directory Driver ST:      (if-operation equal "modify") = FALSE.
    [01/30/25 19:46:50.890]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.891]:Active Directory Driver ST:    Evaluating selection criteria for rule 'lockoutTime: Convert to Identity Vault time format'.
    [01/30/25 19:46:50.891]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:50.891]:Active Directory Driver ST:    Applying rule 'lockoutTime: Convert to Identity Vault time format'.
    [01/30/25 19:46:50.892]:Active Directory Driver ST:      Action: do-reformat-op-attr("lockoutTime",token-xpath("jadutil:translateFileTime2Epoch($current-value)")).
    [01/30/25 19:46:50.893]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.893]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <instance class-name="user" event-id="0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
        </instance>
        <status event-id="0" level="success"/>
      </output>
    </nds>
    [01/30/25 19:46:50.896]:Active Directory Driver ST:Applying policy: %+C%14CNOVLPWDSYNC-itp-EmailOnFailedPwdSub%-C.
    [01/30/25 19:46:50.896]:Active Directory Driver ST:  Applying to instance #1.
    [01/30/25 19:46:50.897]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
    [01/30/25 19:46:50.897]:Active Directory Driver ST:      (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
    [01/30/25 19:46:50.898]:Active Directory Driver ST:      (if-operation equal "status") = FALSE.
    [01/30/25 19:46:50.898]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.898]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Send e-mail on failure to reset connected system password using the Identity Vault password'.
    [01/30/25 19:46:50.899]:Active Directory Driver ST:      (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
    [01/30/25 19:46:50.900]:Active Directory Driver ST:      (if-operation equal "status") = FALSE.
    [01/30/25 19:46:50.900]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.901]:Active Directory Driver ST:  Applying to status #2.
    [01/30/25 19:46:50.901]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Send e-mail on a failure when subscribing to passwords'.
    [01/30/25 19:46:50.902]:Active Directory Driver ST:      (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
    [01/30/25 19:46:50.902]:Active Directory Driver ST:      (if-operation equal "status") = TRUE.
    [01/30/25 19:46:50.903]:Active Directory Driver ST:      (if-xpath true "self::status[@level != 'success'][text() != '']/operation-data/password-subscribe-status/association[text() != '']") = FALSE.
    [01/30/25 19:46:50.903]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.903]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Send e-mail on failure to reset connected system password using the Identity Vault password'.
    [01/30/25 19:46:50.904]:Active Directory Driver ST:      (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
    [01/30/25 19:46:50.905]:Active Directory Driver ST:      (if-operation equal "status") = TRUE.
    [01/30/25 19:46:50.906]:Active Directory Driver ST:      (if-xpath true "self::status[@level != 'success']/operation-data/password-reset-status") = FALSE.
    [01/30/25 19:46:50.906]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.907]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.907]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <instance class-name="user" event-id="0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
        </instance>
        <status event-id="0" level="success"/>
      </output>
    </nds>
    [01/30/25 19:46:50.909]:Active Directory Driver ST:Applying schema mapping policies to input.
    [01/30/25 19:46:50.910]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-smp%-C.
    [01/30/25 19:46:50.911]:Active Directory Driver ST:  No mapping for class-name 'user'.
    [01/30/25 19:46:50.911]:Active Directory Driver ST:Resolving association references.
    [01/30/25 19:46:50.912]:Active Directory Driver ST:Read result:
    [01/30/25 19:46:50.913]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <instance class-name="user" event-id="0" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
        </instance>
        <status event-id="0" level="success"/>
      </output>
    </nds>
    [01/30/25 19:46:50.916]:Active Directory Driver ST:Reading relevant attributes from \IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST.
    [01/30/25 19:46:50.916]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query class-name="User" dest-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" dest-entry-id="34616" scope="entry">
          <read-attr attr-name="DirXML-ADAliasName"/>
          <read-attr attr-name="nspmDistributionPassword"/>
          <read-attr attr-name="workforceID"/>
          <read-attr attr-name="Object Class"/>
        </query>
      </input>
    </nds>
    [01/30/25 19:46:50.919]:Active Directory Driver ST:Pumping XDS to eDirectory.
    [01/30/25 19:46:50.919]:Active Directory Driver ST:Performing operation query for \IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST.
    [01/30/25 19:46:50.920]:Active Directory Driver ST:--JCLNT-- \IDM_TREE\system\driverset1\Active Directory Driver : Duplicating : context = 742523075, tempContext = 742523199
    [01/30/25 19:46:50.922]:Active Directory Driver ST:--JCLNT-- \IDM_TREE\system\driverset1\Active Directory Driver : Calling free on tempContext = 742523199
    [01/30/25 19:46:50.923]:Active Directory Driver ST:Read result:
    [01/30/25 19:46:50.923]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <instance class-name="User" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association state="associated">f20e64655ece484da834bdda58c0d39a</association>
          <attr attr-name="nspmDistributionPassword" is-sensitive="true"><!-- content suppressed -->
          </attr>
          <attr attr-name="Object Class">
            <value timestamp="1738160208#66" type="string">User</value>
            <value timestamp="1738160208#67" type="string">DirXML-ApplicationAttrs</value>
            <value timestamp="1738160208#68" type="string">Organizational Person</value>
            <value timestamp="1738160208#69" type="string">Person</value>
            <value timestamp="1738160208#70" type="string">ndsLoginProperties</value>
            <value timestamp="1738160208#71" type="string">Top</value>
          </attr>
        </instance>
        <status level="success"></status>
      </output>
    </nds>
    [01/30/25 19:46:50.930]:Active Directory Driver ST:Updating eDirectory with application values.
    [01/30/25 19:46:50.931]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" dest-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" dest-entry-id="34616" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="nspmDistributionPassword" is-sensitive="true"><!-- content suppressed -->
          </modify-attr>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:50.934]:Active Directory Driver ST:Applying command transformation policies.
    [01/30/25 19:46:50.934]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-pub-ctp-UserNameMap%-C.
    [01/30/25 19:46:50.934]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:50.935]:Active Directory Driver ST:    Evaluating selection criteria for rule 'consider user objects when name mapping is enabled'.
    [01/30/25 19:46:50.935]:Active Directory Driver ST:      (if-class-name not-equal "User") = FALSE.
    [01/30/25 19:46:50.936]:Active Directory Driver ST:      (if-global-variable 'FullNameMap' equal "false") = FALSE.
    [01/30/25 19:46:50.936]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.936]:Active Directory Driver ST:    Evaluating selection criteria for rule 'full name mapping: discard unwanted renames'.
    [01/30/25 19:46:50.937]:Active Directory Driver ST:      (if-global-variable 'FullNameMap' equal "true") = TRUE.
    [01/30/25 19:46:50.937]:Active Directory Driver ST:      (if-operation equal "rename") = FALSE.
    [01/30/25 19:46:50.938]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.938]:Active Directory Driver ST:    Evaluating selection criteria for rule 'logon name mapping: map NT logon name to Identity Vault object name'.
    [01/30/25 19:46:50.939]:Active Directory Driver ST:      (if-global-variable 'LogonNameMap' equal "true") = TRUE.
    [01/30/25 19:46:50.939]:Active Directory Driver ST:      (if-operation equal "modify") = TRUE.
    [01/30/25 19:46:50.939]:Active Directory Driver ST:      (if-op-attr 'CN' available) = FALSE.
    [01/30/25 19:46:50.940]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.940]:Active Directory Driver ST:    Evaluating selection criteria for rule 'map e-mail address to Active Directory logon name'.
    [01/30/25 19:46:50.941]:Active Directory Driver ST:      (if-global-variable 'UpnMap' equal "ad-mail-auth") = FALSE.
    [01/30/25 19:46:50.941]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.941]:Active Directory Driver ST:    Evaluating selection criteria for rule 'unmap e-mail address from Active Directory logon name'.
    [01/30/25 19:46:50.942]:Active Directory Driver ST:      (if-global-variable 'UpnMap' equal "ad-mail-auth") = FALSE.
    [01/30/25 19:46:50.942]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.943]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.943]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" dest-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" dest-entry-id="34616" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="nspmDistributionPassword" is-sensitive="true"><!-- content suppressed -->
          </modify-attr>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:50.946]:Active Directory Driver ST:Applying policy: %+C%14CNOVLPWDSYNC-pub-cp-DefaultPwd%-C.
    [01/30/25 19:46:50.947]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:50.947]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.947]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" dest-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" dest-entry-id="34616" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="nspmDistributionPassword" is-sensitive="true"><!-- content suppressed -->
          </modify-attr>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:50.950]:Active Directory Driver ST:Applying policy: %+C%14CNOVLPWDSYNC-pub-ctp-CheckPwdGCV%-C.
    [01/30/25 19:46:50.951]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:50.951]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Block publishing passwords to the Identity Vault when adding an object'.
    [01/30/25 19:46:50.951]:Active Directory Driver ST:      (if-global-variable 'enable-password-publish' equal "false") = FALSE.
    [01/30/25 19:46:50.952]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.952]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Block sending modify-password changes to the Identity Vault'.
    [01/30/25 19:46:50.953]:Active Directory Driver ST:      (if-global-variable 'enable-password-publish' equal "false") = FALSE.
    [01/30/25 19:46:50.953]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.954]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.954]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" dest-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" dest-entry-id="34616" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="nspmDistributionPassword" is-sensitive="true"><!-- content suppressed -->
          </modify-attr>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:50.957]:Active Directory Driver ST:Applying policy: %+C%14CNOVLPWDSYNC-pub-ctp-PublishDistPwd%-C.
    [01/30/25 19:46:50.957]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:50.958]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add nspmDistributionAttribute attribute to add operation'.
    [01/30/25 19:46:50.958]:Active Directory Driver ST:      (if-global-variable 'publish-password-to-dp' equal "true") = FALSE.
    [01/30/25 19:46:50.959]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.960]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Change modify-password operations to a modify'.
    [01/30/25 19:46:50.960]:Active Directory Driver ST:      (if-global-variable 'publish-password-to-dp' equal "true") = FALSE.
    [01/30/25 19:46:50.961]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.961]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.962]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" dest-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" dest-entry-id="34616" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="nspmDistributionPassword" is-sensitive="true"><!-- content suppressed -->
          </modify-attr>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:50.966]:Active Directory Driver ST:Applying policy: %+C%14CNOVLPWDSYNC-pub-ctp-PublishNDSPwd%-C.
    [01/30/25 19:46:50.967]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:50.967]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Block publishing passwords to eDirectory password'.
    [01/30/25 19:46:50.968]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:50.968]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.969]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Block sending modify-password changes to the eDirectory password'.
    [01/30/25 19:46:50.970]:Active Directory Driver ST:      (if-operation equal "modify-password") = FALSE.
    [01/30/25 19:46:50.970]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:50.971]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.971]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" dest-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" dest-entry-id="34616" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="nspmDistributionPassword" is-sensitive="true"><!-- content suppressed -->
          </modify-attr>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:50.976]:Active Directory Driver ST:Applying policy: %+C%14CNOVLPWDSYNC-pub-ctp-AddPwdPayload%-C.
    [01/30/25 19:46:50.976]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:50.977]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add operation-data element to password operations'.
    [01/30/25 19:46:50.978]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:50.978]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:50.979]:Active Directory Driver ST:      (if-operation equal "modify-password") = FALSE.
    [01/30/25 19:46:50.979]:Active Directory Driver ST:      (if-operation equal "modify") = TRUE.
    [01/30/25 19:46:50.980]:Active Directory Driver ST:      (if-xpath true "modify-attr[@attr-name='nspmDistributionPassword']") = TRUE.
    [01/30/25 19:46:50.980]:Active Directory Driver ST:      (if-xpath not-true "operation-data") = TRUE.
    [01/30/25 19:46:50.981]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:50.981]:Active Directory Driver ST:    Applying rule 'Add operation-data element to password operations'.
    [01/30/25 19:46:50.982]:Active Directory Driver ST:      Action: do-append-xml-element("operation-data",".").
    [01/30/25 19:46:50.982]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add payload data to password operations'.
    [01/30/25 19:46:50.983]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:50.983]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:50.984]:Active Directory Driver ST:      (if-operation equal "modify-password") = FALSE.
    [01/30/25 19:46:50.984]:Active Directory Driver ST:      (if-operation equal "modify") = TRUE.
    [01/30/25 19:46:50.985]:Active Directory Driver ST:      (if-xpath true "modify-attr[@attr-name='nspmDistributionPassword']") = TRUE.
    [01/30/25 19:46:50.986]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:50.986]:Active Directory Driver ST:    Applying rule 'Add payload data to password operations'.
    [01/30/25 19:46:50.987]:Active Directory Driver ST:      Action: do-append-xml-element("password-publish-status","operation-data").
    [01/30/25 19:46:50.988]:Active Directory Driver ST:      Action: do-append-xml-element("association","operation-data/password-publish-status").
    [01/30/25 19:46:50.988]:Active Directory Driver ST:      Action: do-append-xml-text("operation-data/password-publish-status/association",token-association()).
    [01/30/25 19:46:50.989]:Active Directory Driver ST:        arg-string(token-association())
    [01/30/25 19:46:50.992]:Active Directory Driver ST:          token-association()
    [01/30/25 19:46:50.993]:Active Directory Driver ST:            Token Value: "f20e64655ece484da834bdda58c0d39a".
    [01/30/25 19:46:50.994]:Active Directory Driver ST:          Arg Value: "f20e64655ece484da834bdda58c0d39a".
    [01/30/25 19:46:50.994]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:50.995]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" dest-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" dest-entry-id="34616" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="nspmDistributionPassword" is-sensitive="true"><!-- content suppressed -->
          </modify-attr>
          <operation-data>
            <password-publish-status>
              <association>f20e64655ece484da834bdda58c0d39a</association>
            </password-publish-status>
          </operation-data>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:51.015]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-pub-ctp%-C.
    [01/30/25 19:46:51.015]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:51.016]:Active Directory Driver ST:    Evaluating selection criteria for rule 'set cached context value on merge'.
    [01/30/25 19:46:51.016]:Active Directory Driver ST:      (if-operation equal "modify") = TRUE.
    [01/30/25 19:46:51.017]:Active Directory Driver ST:      (if-xpath true "@from-merge='true'") = TRUE.
    [01/30/25 19:46:51.017]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:51.017]:Active Directory Driver ST:    Applying rule 'set cached context value on merge'.
    [01/30/25 19:46:51.018]:Active Directory Driver ST:      Action: do-add-dest-attr-value("Object Class","DirXML-ApplicationAttrs").
    [01/30/25 19:46:51.019]:Active Directory Driver ST:        arg-string("DirXML-ApplicationAttrs")
    [01/30/25 19:46:51.019]:Active Directory Driver ST:          token-text("DirXML-ApplicationAttrs")
    [01/30/25 19:46:51.020]:Active Directory Driver ST:          Arg Value: "DirXML-ApplicationAttrs".
    [01/30/25 19:46:51.020]:Active Directory Driver ST:      Action: do-set-dest-attr-value("DirXML-ADContext",token-src-dn()).
    [01/30/25 19:46:51.021]:Active Directory Driver ST:        arg-string(token-src-dn())
    [01/30/25 19:46:51.021]:Active Directory Driver ST:          token-src-dn()
    [01/30/25 19:46:51.022]:Active Directory Driver ST:            Token Value: "CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM".
    [01/30/25 19:46:51.022]:Active Directory Driver ST:          Arg Value: "CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM".
    [01/30/25 19:46:51.023]:Active Directory Driver ST:    Evaluating selection criteria for rule 'remove managed attributes when object disassociated'.
    [01/30/25 19:46:51.024]:Active Directory Driver ST:      (if-operation equal "remove-association") = FALSE.
    [01/30/25 19:46:51.024]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:51.025]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Prevent unassociated users from being removed from groups'.
    [01/30/25 19:46:51.025]:Active Directory Driver ST:      (if-operation equal "modify") = TRUE.
    [01/30/25 19:46:51.026]:Active Directory Driver ST:      (if-class-name equal "Group") = FALSE.
    [01/30/25 19:46:51.026]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:51.027]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Set Equivalent To Me when group members change'.
    [01/30/25 19:46:51.027]:Active Directory Driver ST:      (if-class-name equal "Group") = FALSE.
    [01/30/25 19:46:51.028]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:51.028]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Set uniqueID if unavailable'.
    [01/30/25 19:46:51.029]:Active Directory Driver ST:      (if-class-name equal "User") = TRUE.
    [01/30/25 19:46:51.029]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:51.030]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:51.030]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:51.030]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" dest-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" dest-entry-id="34616" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="nspmDistributionPassword" is-sensitive="true"><!-- content suppressed -->
          </modify-attr>
          <operation-data>
            <password-publish-status>
              <association>f20e64655ece484da834bdda58c0d39a</association>
            </password-publish-status>
          </operation-data>
          <modify-attr attr-name="Object Class">
            <add-value>
              <value type="string">DirXML-ApplicationAttrs</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="DirXML-ADContext">
            <remove-all-values/>
            <add-value>
              <value type="string">CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM</value>
            </add-value>
          </modify-attr>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:51.037]:Active Directory Driver ST:Applying XSLT policy: %+C%14CNOVLADDCFG-pub-cts%-C.
    [01/30/25 19:46:51.038]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:51.038]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" dest-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" dest-entry-id="34616" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" src-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="nspmDistributionPassword" is-sensitive="true"><!-- content suppressed -->
          </modify-attr>
          <operation-data>
            <password-publish-status>
              <association>f20e64655ece484da834bdda58c0d39a</association>
            </password-publish-status>
          </operation-data>
          <modify-attr attr-name="Object Class">
            <add-value>
              <value type="string">DirXML-ApplicationAttrs</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="DirXML-ADContext">
            <remove-all-values/>
            <add-value>
              <value type="string">CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM</value>
            </add-value>
          </modify-attr>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:51.045]:Active Directory Driver ST:Filtering out notification-only attributes.
    [01/30/25 19:46:51.045]:Active Directory Driver ST:Stripping operation data from input document
    [01/30/25 19:46:52.695]:Active Directory Driver PT:--JCLNT-- \IDM_TREE\system\driverset1\Active Directory Driver - Publisher : Calling free on tempContext = 742523151
    [01/30/25 19:46:52.695]:Active Directory Driver PT:
    DirXML Log Event -------------------
         Driver:   \IDM_TREE\system\driverset1\Active Directory Driver
         Channel:  Publisher
         Object:   CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM (data\users\SYSTEMD-NEW\SERVER_TEST)
         Status:   Success
    [01/30/25 19:46:52.696]:Active Directory Driver ST:Pumping XDS to eDirectory.
    [01/30/25 19:46:52.697]:Active Directory Driver PT:Fixing up association references.
    [01/30/25 19:46:52.698]:Active Directory Driver PT:Applying schema mapping policies to output.
    [01/30/25 19:46:52.698]:Active Directory Driver PT:Applying policy: %+C%14CNOVLADDCFG-smp%-C.
    [01/30/25 19:46:52.697]:Active Directory Driver ST:Performing operation modify for \IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST.
    [01/30/25 19:46:52.699]:Active Directory Driver PT:Applying output transformation policies.
    [01/30/25 19:46:52.700]:Active Directory Driver ST:--JCLNT-- \IDM_TREE\system\driverset1\Active Directory Driver : Duplicating : context = 742523169, tempContext = 742523151
    [01/30/25 19:46:52.700]:Active Directory Driver PT:Applying policy: %+C%14CNOVLADDCFG-otp-FormatConversions%-C.
    [01/30/25 19:46:52.701]:Active Directory Driver ST:Modifying entry \IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST.
    [01/30/25 19:46:52.701]:Active Directory Driver PT:  Applying to status #1.
    [01/30/25 19:46:52.702]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
    [01/30/25 19:46:52.703]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" dest-dn="CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="nspmDistributionPassword" failed-sync="true"><!-- content suppressed -->
          </modify-attr>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:52.703]:Active Directory Driver PT:    Rule selected.
    [01/30/25 19:46:52.707]:Active Directory Driver PT:    Applying rule 'Street Address: Convert LF to CR-LF'.
    [01/30/25 19:46:52.707]:Active Directory Driver PT:      Action: do-set-local-variable("CR-LF",scope="policy",token-char(value="13")+token-char(value="10")).
    [01/30/25 19:46:52.708]:Active Directory Driver ST:--JCLNT-- \IDM_TREE\system\driverset1\Active Directory Driver : Calling free on tempContext = 742523151
    [01/30/25 19:46:52.708]:Active Directory Driver PT:        arg-string(token-char(value="13")+token-char(value="10"))
    [01/30/25 19:46:52.710]:Active Directory Driver PT:          token-char(value="13")
    [01/30/25 19:46:52.710]:Active Directory Driver PT:            Token Value: "
    ".
    [01/30/25 19:46:52.711]:Active Directory Driver PT:          token-char(value="10")
    [01/30/25 19:46:52.711]:Active Directory Driver ST:Restoring operation data to output document
    [01/30/25 19:46:52.711]:Active Directory Driver PT:            Token Value: "
    ".
    [01/30/25 19:46:52.712]:Active Directory Driver ST:
    DirXML Log Event -------------------
         Driver:   \IDM_TREE\system\driverset1\Active Directory Driver
         Channel:  Subscriber
         Object:   \IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST
         Status:   Success
    [01/30/25 19:46:52.712]:Active Directory Driver PT:          Arg Value: "
    ".
    [01/30/25 19:46:52.714]:Active Directory Driver ST:
    DirXML Log Event -------------------
         Driver:   \IDM_TREE\system\driverset1\Active Directory Driver
         Channel:  Subscriber
         Object:   \IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST
         Status:   Warning
         Message:  Code(-8021) Unable to set NMAS password: -1643 NMAS_E_INVALID_PARAMETER.
    [01/30/25 19:46:52.714]:Active Directory Driver PT:      Action: do-reformat-op-attr("streetAddress",token-replace-all("(?<!\r)\n","$CR-LF$",token-local-variable("current-value"))).
    [01/30/25 19:46:52.716]:Active Directory Driver ST:Updating application with eDirectory values.
    [01/30/25 19:46:52.717]:Active Directory Driver PT:    Evaluating selection criteria for rule 'logonHours: Convert to Active Directory form'.
    [01/30/25 19:46:52.717]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:52.718]:Active Directory Driver PT:    Rule selected.
    [01/30/25 19:46:52.727]:Active Directory Driver ST:Applying command transformation policies.
    [01/30/25 19:46:52.727]:Active Directory Driver PT:    Applying rule 'logonHours: Convert to Active Directory form'.
    [01/30/25 19:46:52.727]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-sub-ctp-GroupMemberResolution%-C.
    [01/30/25 19:46:52.728]:Active Directory Driver PT:      Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
    [01/30/25 19:46:52.729]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:52.729]:Active Directory Driver PT:    Evaluating selection criteria for rule 'accountExpires: Convert to Active Directory form'.
    [01/30/25 19:46:52.730]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add new user to associated groups'.
    [01/30/25 19:46:52.730]:Active Directory Driver PT:      (if-op-attr 'accountExpires' changing) = FALSE.
    [01/30/25 19:46:52.731]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:52.732]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.732]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:52.733]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:52.733]:Active Directory Driver PT:    Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
    [01/30/25 19:46:52.733]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:52.734]:Active Directory Driver PT:      (if-op-attr 'lockoutTime' available) = FALSE.
    [01/30/25 19:46:52.743]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-sub-ctp-HandleMovesAndRenames%-C.
    [01/30/25 19:46:52.744]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:52.745]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:52.745]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
    [01/30/25 19:46:52.746]:Active Directory Driver ST:    Evaluating selection criteria for rule 'associate mirror root'.
    [01/30/25 19:46:52.747]:Active Directory Driver PT:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:52.747]:Active Directory Driver ST:      (if-operation equal "move") = FALSE.
    [01/30/25 19:46:52.748]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:52.748]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.749]:Active Directory Driver PT:    Evaluating selection criteria for rule 'update Active Directory logon name'.
    [01/30/25 19:46:52.749]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:52.750]:Active Directory Driver PT:      (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
    [01/30/25 19:46:52.750]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
      </input>
    </nds>
    [01/30/25 19:46:52.751]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:52.762]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-sub-ctp-UserNameMap%-C.
    [01/30/25 19:46:52.762]:Active Directory Driver PT:Policy returned:
    [01/30/25 19:46:52.763]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:52.763]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##194b26bee52##0" level="success"><application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM (data\users\SYSTEMD-NEW\SERVER_TEST)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [01/30/25 19:46:52.763]:Active Directory Driver ST:    Evaluating selection criteria for rule 'consider user objects when name mapping is enabled'.
    [01/30/25 19:46:52.767]:Active Directory Driver PT:Applying policy: %+C%14CNOVLADDCFG-otp-ExchangeEntitlementQuery%-C.
    [01/30/25 19:46:52.768]:Active Directory Driver ST:      (if-class-name not-equal "User") = FALSE.
    [01/30/25 19:46:52.768]:Active Directory Driver PT:  Applying to status #1.
    [01/30/25 19:46:52.769]:Active Directory Driver ST:      (if-global-variable 'FullNameMap' equal "false") = FALSE.
    [01/30/25 19:46:52.770]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.770]:Active Directory Driver ST:    Evaluating selection criteria for rule 'generate full name on merge'.
    [01/30/25 19:46:52.771]:Active Directory Driver ST:      (if-global-variable 'FullNameMap' equal "true") = TRUE.
    [01/30/25 19:46:52.770]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Add dest-dn to the Exchange Entitlement Query'.
    [01/30/25 19:46:52.772]:Active Directory Driver ST:      (if-xpath true ".[@from-merge='true']") = TRUE.
    [01/30/25 19:46:52.773]:Active Directory Driver PT:      (if-operation match "query|query-ex") = FALSE.
    [01/30/25 19:46:52.773]:Active Directory Driver ST:      (if-attr 'Full Name' not-available) = FALSE.
    [01/30/25 19:46:52.774]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:52.775]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.776]:Active Directory Driver ST:    Evaluating selection criteria for rule 'map full name to destination object name'.
    [01/30/25 19:46:52.775]:Active Directory Driver PT:Policy returned:
    [01/30/25 19:46:52.776]:Active Directory Driver ST:      (if-global-variable 'FullNameMap' equal "true") = TRUE.
    [01/30/25 19:46:52.777]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##194b26bee52##0" level="success"><application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM (data\users\SYSTEMD-NEW\SERVER_TEST)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [01/30/25 19:46:52.778]:Active Directory Driver ST:      (if-operation equal "modify") = TRUE.
    [01/30/25 19:46:52.781]:Active Directory Driver PT:Applying policy: %+C%14CNOVLPWDSYNC-otp-EmailOnFailedPwdPub%-C.
    [01/30/25 19:46:52.782]:Active Directory Driver ST:      (if-op-attr 'Full Name' available) = TRUE.
    [01/30/25 19:46:52.782]:Active Directory Driver PT:  Applying to status #1.
    [01/30/25 19:46:52.783]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:52.784]:Active Directory Driver ST:    Applying rule 'map full name to destination object name'.
    [01/30/25 19:46:52.783]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Send e-mail for a failed publish password operation'.
    [01/30/25 19:46:52.785]:Active Directory Driver PT:      (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
    [01/30/25 19:46:52.786]:Active Directory Driver PT:      (if-operation equal "status") = TRUE.
    [01/30/25 19:46:52.786]:Active Directory Driver PT:      (if-xpath true "self::status[@level != 'success']/operation-data/password-publish-status") = FALSE.
    [01/30/25 19:46:52.784]:Active Directory Driver ST:      Action: do-rename-dest-object(when="after",token-escape-for-dest-dn(token-op-attr("Full Name"))).
    [01/30/25 19:46:52.787]:Active Directory Driver PT:    Rule rejected.
    [01/30/25 19:46:52.788]:Active Directory Driver ST:        arg-string(token-escape-for-dest-dn(token-op-attr("Full Name")))
    [01/30/25 19:46:52.789]:Active Directory Driver PT:Policy returned:
    [01/30/25 19:46:52.789]:Active Directory Driver ST:          token-escape-for-dest-dn(token-op-attr("Full Name"))
    [01/30/25 19:46:52.790]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##194b26bee52##0" level="success"><application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM (data\users\SYSTEMD-NEW\SERVER_TEST)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [01/30/25 19:46:52.790]:Active Directory Driver ST:            token-escape-for-dest-dn(token-op-attr("Full Name"))
    [01/30/25 19:46:52.794]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##194b26bee52##0" level="success"><application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM (data\users\SYSTEMD-NEW\SERVER_TEST)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [01/30/25 19:46:52.797]:Active Directory Driver PT:Remote Interface Driver: Sending...
    [01/30/25 19:46:52.794]:Active Directory Driver ST:              token-op-attr("Full Name")
    [01/30/25 19:46:52.798]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##194b26bee52##0" level="success"><application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=SERVER_TEST,OU=SYSTEMD-OLD,DC=PVT,DC=DOMINO,DC=COM (data\users\SYSTEMD-NEW\SERVER_TEST)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [01/30/25 19:46:52.799]:Active Directory Driver ST:                Token Value: "SERVER_TEST".
    [01/30/25 19:46:52.803]:Active Directory Driver PT:Remote Interface Driver: Document sent.
    [01/30/25 19:46:52.804]:Active Directory Driver ST:              Arg Value: "SERVER_TEST".
    [01/30/25 19:46:52.804]:Active Directory Driver PT:Remote Interface Driver: Waiting for receive...
    [01/30/25 19:46:52.805]:Active Directory Driver ST:            Token Value: "SERVER_TEST".
    [01/30/25 19:46:52.806]:Active Directory Driver ST:          Arg Value: "SERVER_TEST".
    [01/30/25 19:46:52.807]:Active Directory Driver ST:    Evaluating selection criteria for rule 'escape source object name'.
    [01/30/25 19:46:52.807]:Active Directory Driver ST:      (if-operation equal "rename") = FALSE.
    [01/30/25 19:46:52.808]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.808]:Active Directory Driver ST:    Evaluating selection criteria for rule 'map rename to NT logon name'.
    [01/30/25 19:46:52.809]:Active Directory Driver ST:      (if-global-variable 'LogonNameMap' equal "true") = TRUE.
    [01/30/25 19:46:52.810]:Active Directory Driver ST:      (if-operation equal "rename") = FALSE.
    [01/30/25 19:46:52.810]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.811]:Active Directory Driver ST:    Evaluating selection criteria for rule 'map rename to Active Directory logon name'.
    [01/30/25 19:46:52.812]:Active Directory Driver ST:      (if-global-variable 'UpnMap' equal "edir-name-auth") = TRUE.
    [01/30/25 19:46:52.812]:Active Directory Driver ST:      (if-operation equal "rename") = FALSE.
    [01/30/25 19:46:52.813]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.813]:Active Directory Driver ST:    Evaluating selection criteria for rule 'map e-mail address to Active Directory logon name'.
    [01/30/25 19:46:52.814]:Active Directory Driver ST:      (if-global-variable 'UpnMap' equal "edir-mail-auth") = FALSE.
    [01/30/25 19:46:52.815]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.815]:Active Directory Driver ST:    Evaluating selection criteria for rule 'unmap e-mail address from Active Directory logon name'.
    [01/30/25 19:46:52.816]:Active Directory Driver ST:      (if-global-variable 'UpnMap' equal "edir-mail-auth") = FALSE.
    [01/30/25 19:46:52.817]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.818]:Active Directory Driver ST:    Evaluating selection criteria for rule 'map e-mail address to Active Directory logon name on merge'.
    [01/30/25 19:46:52.819]:Active Directory Driver ST:      (if-global-variable 'UpnMap' equal "edir-mail-auth") = FALSE.
    [01/30/25 19:46:52.819]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.820]:Active Directory Driver ST:    Evaluating selection criteria for rule 'unmap e-mail address from Active Directory logon name on merge'.
    [01/30/25 19:46:52.820]:Active Directory Driver ST:      (if-global-variable 'UpnMap' equal "edir-mail-auth") = FALSE.
    [01/30/25 19:46:52.821]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.821]:Active Directory Driver ST:    Evaluating selection criteria for rule 'discard unwanted renames'.
    [01/30/25 19:46:52.822]:Active Directory Driver ST:      (if-global-variable 'FullNameMap' equal "true") = TRUE.
    [01/30/25 19:46:52.822]:Active Directory Driver ST:      (if-operation equal "rename") = FALSE.
    [01/30/25 19:46:52.823]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.823]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:52.824]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
        <rename class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <new-name>SERVER_TEST</new-name>
        </rename>
      </input>
    </nds>
    [01/30/25 19:46:52.835]:Active Directory Driver ST:Applying policy: %+C%14CNOVLPWDSYNC-sub-ctp-TransformDistPwd%-C.
    [01/30/25 19:46:52.835]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:52.836]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Convert adds of the nspmDistributionPassword attribute to password elements'.
    [01/30/25 19:46:52.836]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:52.837]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.837]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Block modifies for failed password publish operations if reset password is false'.
    [01/30/25 19:46:52.838]:Active Directory Driver ST:      (if-global-variable 'reset-external-password-on-failure' equal "false") = FALSE.
    [01/30/25 19:46:52.839]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.839]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Convert modifies of a nspmDistributionPassword attribute to a modify password operation'.
    [01/30/25 19:46:52.840]:Active Directory Driver ST:      (if-operation equal "modify") = TRUE.
    [01/30/25 19:46:52.841]:Active Directory Driver ST:      (if-op-attr 'nspmDistributionPassword' available) = FALSE.
    [01/30/25 19:46:52.841]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.842]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Block empty modify operations'.
    [01/30/25 19:46:52.842]:Active Directory Driver ST:      (if-operation equal "modify") = TRUE.
    [01/30/25 19:46:52.843]:Active Directory Driver ST:      (if-xpath not-true "modify-attr") = FALSE.
    [01/30/25 19:46:52.843]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.843]:Active Directory Driver ST:  Applying to rename #2.
    [01/30/25 19:46:52.844]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Convert adds of the nspmDistributionPassword attribute to password elements'.
    [01/30/25 19:46:52.845]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:52.845]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.845]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Block modifies for failed password publish operations if reset password is false'.
    [01/30/25 19:46:52.846]:Active Directory Driver ST:      (if-global-variable 'reset-external-password-on-failure' equal "false") = FALSE.
    [01/30/25 19:46:52.847]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.847]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Convert modifies of a nspmDistributionPassword attribute to a modify password operation'.
    [01/30/25 19:46:52.848]:Active Directory Driver ST:      (if-operation equal "modify") = FALSE.
    [01/30/25 19:46:52.848]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.849]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Block empty modify operations'.
    [01/30/25 19:46:52.849]:Active Directory Driver ST:      (if-operation equal "modify") = FALSE.
    [01/30/25 19:46:52.850]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.850]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:52.850]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
        <rename class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <new-name>SERVER_TEST</new-name>
        </rename>
      </input>
    </nds>
    [01/30/25 19:46:52.862]:Active Directory Driver ST:Applying policy: %+C%14CNOVLPWDSYNC-sub-cp-DefaultPwd%-C.
    [01/30/25 19:46:52.862]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:52.862]:Active Directory Driver ST:    Evaluating selection criteria for rule 'On User add, provide default password if no password exists'.
    [01/30/25 19:46:52.863]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:52.864]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.864]:Active Directory Driver ST:  Applying to rename #2.
    [01/30/25 19:46:52.864]:Active Directory Driver ST:    Evaluating selection criteria for rule 'On User add, provide default password if no password exists'.
    [01/30/25 19:46:52.865]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:52.866]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.866]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:52.867]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
        <rename class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <new-name>SERVER_TEST</new-name>
        </rename>
      </input>
    </nds>
    [01/30/25 19:46:52.877]:Active Directory Driver ST:Applying policy: %+C%14CNOVLPWDSYNC-sub-ctp-CheckPwdGCV%-C.
    [01/30/25 19:46:52.878]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:52.878]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Block subscribing to passwords when objects are added'.
    [01/30/25 19:46:52.879]:Active Directory Driver ST:      (if-global-variable 'enable-password-subscribe' equal "false") = FALSE.
    [01/30/25 19:46:52.880]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.880]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Block subscribing to password modifications'.
    [01/30/25 19:46:52.881]:Active Directory Driver ST:      (if-global-variable 'enable-password-subscribe' equal "false") = FALSE.
    [01/30/25 19:46:52.881]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.882]:Active Directory Driver ST:  Applying to rename #2.
    [01/30/25 19:46:52.882]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Block subscribing to passwords when objects are added'.
    [01/30/25 19:46:52.883]:Active Directory Driver ST:      (if-global-variable 'enable-password-subscribe' equal "false") = FALSE.
    [01/30/25 19:46:52.883]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.884]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Block subscribing to password modifications'.
    [01/30/25 19:46:52.884]:Active Directory Driver ST:      (if-global-variable 'enable-password-subscribe' equal "false") = FALSE.
    [01/30/25 19:46:52.885]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.885]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:52.886]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
        <rename class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <new-name>SERVER_TEST</new-name>
        </rename>
      </input>
    </nds>
    [01/30/25 19:46:52.900]:Active Directory Driver ST:Applying policy: %+C%14CNOVLPWDSYNC-sub-ctp-AddPwdPayload%-C.
    [01/30/25 19:46:52.900]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:52.901]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add operation-data element to password subscribe operations'.
    [01/30/25 19:46:52.901]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:52.902]:Active Directory Driver ST:      (if-operation equal "modify-password") = FALSE.
    [01/30/25 19:46:52.902]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.903]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add payload data to a reset password from a failed password publish operation'.
    [01/30/25 19:46:52.903]:Active Directory Driver ST:      (if-operation equal "modify-password") = FALSE.
    [01/30/25 19:46:52.904]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.904]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add payload data to password subscribe operations'.
    [01/30/25 19:46:52.905]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:52.905]:Active Directory Driver ST:      (if-operation equal "modify-password") = FALSE.
    [01/30/25 19:46:52.906]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.906]:Active Directory Driver ST:  Applying to rename #2.
    [01/30/25 19:46:52.906]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add operation-data element to password subscribe operations'.
    [01/30/25 19:46:52.907]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:52.908]:Active Directory Driver ST:      (if-operation equal "modify-password") = FALSE.
    [01/30/25 19:46:52.908]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.908]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add payload data to a reset password from a failed password publish operation'.
    [01/30/25 19:46:52.909]:Active Directory Driver ST:      (if-operation equal "modify-password") = FALSE.
    [01/30/25 19:46:52.910]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.910]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add payload data to password subscribe operations'.
    [01/30/25 19:46:52.911]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:52.911]:Active Directory Driver ST:      (if-operation equal "modify-password") = FALSE.
    [01/30/25 19:46:52.912]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.912]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:52.913]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
        <rename class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <new-name>SERVER_TEST</new-name>
        </rename>
      </input>
    </nds>
    [01/30/25 19:46:52.923]:Active Directory Driver ST:Filtering out notification-only attributes.
    [01/30/25 19:46:52.924]:Active Directory Driver ST:Fixing up association references.
    [01/30/25 19:46:52.924]:Active Directory Driver ST:Applying schema mapping policies to output.
    [01/30/25 19:46:52.925]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-smp%-C.
    [01/30/25 19:46:52.925]:Active Directory Driver ST:  No mapping for class-name 'User'.
    [01/30/25 19:46:52.926]:Active Directory Driver ST:  No mapping for class-name 'User'.
    [01/30/25 19:46:52.926]:Active Directory Driver ST:Applying output transformation policies.
    [01/30/25 19:46:52.927]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-otp-FormatConversions%-C.
    [01/30/25 19:46:52.927]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:52.928]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
    [01/30/25 19:46:52.928]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:52.929]:Active Directory Driver ST:    Applying rule 'Street Address: Convert LF to CR-LF'.
    [01/30/25 19:46:52.929]:Active Directory Driver ST:      Action: do-set-local-variable("CR-LF",scope="policy",token-char(value="13")+token-char(value="10")).
    [01/30/25 19:46:52.930]:Active Directory Driver ST:        arg-string(token-char(value="13")+token-char(value="10"))
    [01/30/25 19:46:52.931]:Active Directory Driver ST:          token-char(value="13")
    [01/30/25 19:46:52.931]:Active Directory Driver ST:            Token Value: "
    ".
    [01/30/25 19:46:52.931]:Active Directory Driver ST:          token-char(value="10")
    [01/30/25 19:46:52.932]:Active Directory Driver ST:            Token Value: "
    ".
    [01/30/25 19:46:52.932]:Active Directory Driver ST:          Arg Value: "
    ".
    [01/30/25 19:46:52.933]:Active Directory Driver ST:      Action: do-reformat-op-attr("streetAddress",token-replace-all("(?<!\r)\n","$CR-LF$",token-local-variable("current-value"))).
    [01/30/25 19:46:52.934]:Active Directory Driver ST:    Evaluating selection criteria for rule 'logonHours: Convert to Active Directory form'.
    [01/30/25 19:46:52.934]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:52.935]:Active Directory Driver ST:    Applying rule 'logonHours: Convert to Active Directory form'.
    [01/30/25 19:46:52.935]:Active Directory Driver ST:      Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
    [01/30/25 19:46:52.936]:Active Directory Driver ST:    Evaluating selection criteria for rule 'accountExpires: Convert to Active Directory form'.
    [01/30/25 19:46:52.937]:Active Directory Driver ST:      (if-op-attr 'accountExpires' changing) = FALSE.
    [01/30/25 19:46:52.937]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.938]:Active Directory Driver ST:    Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
    [01/30/25 19:46:52.939]:Active Directory Driver ST:      (if-op-attr 'lockoutTime' available) = FALSE.
    [01/30/25 19:46:52.939]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.939]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
    [01/30/25 19:46:52.940]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:52.941]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.941]:Active Directory Driver ST:    Evaluating selection criteria for rule 'update Active Directory logon name'.
    [01/30/25 19:46:52.942]:Active Directory Driver ST:      (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
    [01/30/25 19:46:52.943]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.943]:Active Directory Driver ST:  Applying to rename #2.
    [01/30/25 19:46:52.943]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Street Address: Convert LF to CR-LF'.
    [01/30/25 19:46:52.944]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:52.944]:Active Directory Driver ST:    Applying rule 'Street Address: Convert LF to CR-LF'.
    [01/30/25 19:46:52.945]:Active Directory Driver ST:      Action: do-set-local-variable("CR-LF",scope="policy",token-char(value="13")+token-char(value="10")).
    [01/30/25 19:46:52.946]:Active Directory Driver ST:        arg-string(token-char(value="13")+token-char(value="10"))
    [01/30/25 19:46:52.946]:Active Directory Driver ST:          token-char(value="13")
    [01/30/25 19:46:52.947]:Active Directory Driver ST:            Token Value: "
    ".
    [01/30/25 19:46:52.947]:Active Directory Driver ST:          token-char(value="10")
    [01/30/25 19:46:52.948]:Active Directory Driver ST:            Token Value: "
    ".
    [01/30/25 19:46:52.948]:Active Directory Driver ST:          Arg Value: "
    ".
    [01/30/25 19:46:52.948]:Active Directory Driver ST:      Action: do-reformat-op-attr("streetAddress",token-replace-all("(?<!\r)\n","$CR-LF$",token-local-variable("current-value"))).
    [01/30/25 19:46:52.949]:Active Directory Driver ST:    Evaluating selection criteria for rule 'logonHours: Convert to Active Directory form'.
    [01/30/25 19:46:52.950]:Active Directory Driver ST:    Rule selected.
    [01/30/25 19:46:52.950]:Active Directory Driver ST:    Applying rule 'logonHours: Convert to Active Directory form'.
    [01/30/25 19:46:52.951]:Active Directory Driver ST:      Action: do-reformat-op-attr("logonHours",token-xpath("jadutil:translateTimeMap2ADLenient($current-value)")).
    [01/30/25 19:46:52.952]:Active Directory Driver ST:    Evaluating selection criteria for rule 'accountExpires: Convert to Active Directory form'.
    [01/30/25 19:46:52.953]:Active Directory Driver ST:      (if-op-attr 'accountExpires' changing) = FALSE.
    [01/30/25 19:46:52.953]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.954]:Active Directory Driver ST:    Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
    [01/30/25 19:46:52.954]:Active Directory Driver ST:      (if-op-attr 'lockoutTime' available) = FALSE.
    [01/30/25 19:46:52.955]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.955]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
    [01/30/25 19:46:52.956]:Active Directory Driver ST:      (if-operation equal "add") = FALSE.
    [01/30/25 19:46:52.956]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.957]:Active Directory Driver ST:    Evaluating selection criteria for rule 'update Active Directory logon name'.
    [01/30/25 19:46:52.958]:Active Directory Driver ST:      (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
    [01/30/25 19:46:52.958]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.959]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:52.959]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
        <rename class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <new-name>SERVER_TEST</new-name>
        </rename>
      </input>
    </nds>
    [01/30/25 19:46:52.970]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-otp-ExchangeEntitlementQuery%-C.
    [01/30/25 19:46:52.971]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:52.971]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add dest-dn to the Exchange Entitlement Query'.
    [01/30/25 19:46:52.972]:Active Directory Driver ST:      (if-operation match "query|query-ex") = FALSE.
    [01/30/25 19:46:52.972]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.973]:Active Directory Driver ST:  Applying to rename #2.
    [01/30/25 19:46:52.973]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Add dest-dn to the Exchange Entitlement Query'.
    [01/30/25 19:46:52.974]:Active Directory Driver ST:      (if-operation match "query|query-ex") = FALSE.
    [01/30/25 19:46:52.974]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.975]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:52.975]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
        <rename class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <new-name>SERVER_TEST</new-name>
        </rename>
      </input>
    </nds>
    [01/30/25 19:46:52.986]:Active Directory Driver ST:Applying policy: %+C%14CNOVLPWDSYNC-otp-EmailOnFailedPwdPub%-C.
    [01/30/25 19:46:52.986]:Active Directory Driver ST:  Applying to modify #1.
    [01/30/25 19:46:52.987]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Send e-mail for a failed publish password operation'.
    [01/30/25 19:46:52.988]:Active Directory Driver ST:      (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
    [01/30/25 19:46:52.988]:Active Directory Driver ST:      (if-operation equal "status") = FALSE.
    [01/30/25 19:46:52.989]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.989]:Active Directory Driver ST:  Applying to rename #2.
    [01/30/25 19:46:52.989]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Send e-mail for a failed publish password operation'.
    [01/30/25 19:46:52.990]:Active Directory Driver ST:      (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = TRUE.
    [01/30/25 19:46:52.991]:Active Directory Driver ST:      (if-operation equal "status") = FALSE.
    [01/30/25 19:46:52.991]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:52.991]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:52.992]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
        <rename class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <new-name>SERVER_TEST</new-name>
        </rename>
      </input>
    </nds>
    [01/30/25 19:46:53.003]:Active Directory Driver ST:Submitting document to subscriber shim:
    [01/30/25 19:46:53.003]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
        <rename class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <new-name>SERVER_TEST</new-name>
        </rename>
      </input>
    </nds>
    [01/30/25 19:46:53.014]:Active Directory Driver ST:Remote Interface Driver: Sending...
    [01/30/25 19:46:53.014]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.7.0000">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" from-merge="true" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <modify-attr attr-name="Login Expiration Time">
            <add-value>
              <value timestamp="1738160208#29" type="time">-1</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Surname">
            <add-value>
              <value timestamp="1738160208#45" type="string">UNKNOWN</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Given Name">
            <add-value>
              <value timestamp="1738160208#48" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Allowed Time Map">
            <add-value>
              <value timestamp="1738160208#27" type="octet">////////////////////////////////////////////////////////</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Login Disabled">
            <add-value>
              <value timestamp="1738160208#28" type="state">false</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="Full Name">
            <add-value>
              <value timestamp="1738160208#47" type="string">SERVER_TEST</value>
            </add-value>
          </modify-attr>
        </modify>
        <rename class-name="User" event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" qualified-src-dn="O=data\OU=users\OU=SYSTEMD-OLD\CN=SERVER_TEST" src-dn="\IDM_TREE\data\users\SYSTEMD-OLD\SERVER_TEST" src-entry-id="34616">
          <association>f20e64655ece484da834bdda58c0d39a</association>
          <new-name>SERVER_TEST</new-name>
        </rename>
      </input>
    </nds>
    [01/30/25 19:46:53.025]:Active Directory Driver ST:Remote Interface Driver: Document sent.
    [01/30/25 19:46:53.025]:Active Directory Driver ST:Remote Interface Driver: Waiting for receive...
    [01/30/25 19:46:53.051]:Active Directory Driver ST:Remote Interface Driver: Received
    [01/30/25 19:46:53.051]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" level="success"/>
        <status event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" level="success"/>
      </output>
    </nds>
    [01/30/25 19:46:53.054]:Active Directory Driver ST:Remote Interface Driver: Received command: SUBSCRIBER REPLY(10).
    [01/30/25 19:46:53.054]:Active Directory Driver ST:SubscriptionShim.execute() returned:
    [01/30/25 19:46:53.055]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" level="success"/>
        <status event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" level="success"/>
      </output>
    </nds>
    [01/30/25 19:46:53.057]:Active Directory Driver ST:Applying input transformation policies.
    [01/30/25 19:46:53.058]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADDCFG-itp-SubscriberUserAdd%-C.
    [01/30/25 19:46:53.058]:Active Directory Driver ST:  Applying to status #1.
    [01/30/25 19:46:53.059]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Populate DirXML-ADContext on initial user add'.
    [01/30/25 19:46:53.060]:Active Directory Driver ST:      (if-operation equal "add-association") = FALSE.
    [01/30/25 19:46:53.060]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:53.060]:Active Directory Driver ST:  Applying to status #2.
    [01/30/25 19:46:53.061]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Populate DirXML-ADContext on initial user add'.
    [01/30/25 19:46:53.062]:Active Directory Driver ST:      (if-operation equal "add-association") = FALSE.
    [01/30/25 19:46:53.062]:Active Directory Driver ST:    Rule rejected.
    [01/30/25 19:46:53.063]:Active Directory Driver ST:Policy returned:
    [01/30/25 19:46:53.063]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20230927_120000" instance="\IDM_TREE\system\driverset1\Active Directory Driver" version="4.1.3.0500">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" level="success"/>
        <status event-id="NIDM-SYS#20250129141650#3#2:de934a2d-fd65-4106-a52f-2d4a93de65fd" level="success"/>
      </output>
    </nds>
    

  • 0   in reply to 

    What is the Merge Authority set to, on the nspmDistributiionPassword attribute in the filter?  Should be set to Default.

  • 0 in reply to   

    It is already set to Default.

  • 0   in reply to 

    So going back to your original question, you called it a password reset.

    What we see in trace is a sync of the current password to AD.

    Why did you think reset?

    I suppose you could set the merge authority on nspmDistributionPassword to None and it won't try to send it.