Exchange mailbox problem

Good afternoon
 We have a problem provisioning Exchange email accounts.
We assing AD and Exchange accounts resources through a level 30 role.


In some cases, Exchange account is assigned a few moments before AD account. Therefore, the event is vetoed.
Aftherthat thanks to the rule: "Check target of add-association for Exchange mailbox entitlements" from policy "NOVLADENTEXT-itp-EntitlementsImpl" an attempt is made to set homeMDB to create the email account.
"set source attribute value (homeMDB)" action succeeds against the "add-association" event, but the corresponding MODIFY <modified-attr attr-name = "homeMDB" does not appear in the output XML . Therefore email account is not created.


My hypothesis is that when the action was executed, Dirxml-association with AD driver had not finished writing to eDir yet.
Action was executed at 19:14:23 hs. and dirxml-association finished writing at 19:14:47 hs.

Here are the log snippets:


Rule "Check target of add-association for Exchange mailbox entitlements":

--------

[11/19/21 19:14:23.355]:Active Directory Driver ST: Action: do-set-src-attr-value("homeMDB",arg-association(token-xpath("./text()")),token-local-variable("homeMDB")).
[11/19/21 19:14:23.355]:Active Directory Driver ST: arg-association(token-xpath("./text()"))
[11/19/21 19:14:23.355]:Active Directory Driver ST: token-xpath("./text()")
[11/19/21 19:14:23.355]:Active Directory Driver ST: Token Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
[11/19/21 19:14:23.370]:Active Directory Driver ST: Arg Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
[11/19/21 19:14:23.370]:Active Directory Driver ST: arg-string(token-local-variable("homeMDB"))
[11/19/21 19:14:23.370]:Active Directory Driver ST: token-local-variable("homeMDB")
[11/19/21 19:14:23.370]:Active Directory Driver ST: Token Value: "CN=New Base 60MG,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=XXXX,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=XXXX,DC=local".
[11/19/21 19:14:23.386]:Active Directory Driver ST: Arg Value: "CN=New Base 60MG,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=XXXX,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=XXXXX,DC=local".
[11/19/21 19:14:23.386]:Active Directory Driver ST: Action: do-set-src-attr-value("mailNickname",arg-association(token-xpath("./text()")),token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name()))).
[11/19/21 19:14:23.401]:Active Directory Driver ST: arg-association(token-xpath("./text()"))
[11/19/21 19:14:23.401]:Active Directory Driver ST: token-xpath("./text()")
[11/19/21 19:14:23.401]:Active Directory Driver ST: Token Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
[11/19/21 19:14:23.401]:Active Directory Driver ST: Arg Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
[11/19/21 19:14:23.401]:Active Directory Driver ST: arg-string(token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name())))
[11/19/21 19:14:23.417]:Active Directory Driver ST: token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name()))
[11/19/21 19:14:23.417]:Active Directory Driver ST: token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name()))
[11/19/21 19:14:23.433]:Active Directory Driver ST: token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name())
[11/19/21 19:14:23.433]:Active Directory Driver ST: token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name())
[11/19/21 19:14:23.433]:Active Directory Driver ST: token-src-name()
[11/19/21 19:14:23.433]:Active Directory Driver ST: Token Value: "".
[11/19/21 19:14:23.433]:Active Directory Driver ST: Arg Value: "".
[11/19/21 19:14:23.433]:Active Directory Driver ST: Token Value: "".
[11/19/21 19:14:23.433]:Active Directory Driver ST: Arg Value: "".
[11/19/21 19:14:23.433]:Active Directory Driver ST: Token Value: "".
[11/19/21 19:14:23.433]:Active Directory Driver ST: Arg Value: "".
[11/19/21 19:14:23.433]:Active Directory Driver ST: Direct command from policy
[11/19/21 19:14:23.433]:Active Directory Driver ST:


<nds dtdversion="4.0" ndsversion="8.x">
<source>
<product edition="Advanced" version="4.8.3.1">DirXML</product>
<contact>NetIQ Corporation</contact>
</source>
<input>
<modify class-name="group" event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128">
<association>19d7d87749815c4bb6182a3293db8d63</association>
<modify-attr attr-name="member">
<add-value>
<value association-ref="1600fb61f1f4af4d93d4da4ba4cb15a2" type="dn">\XXXXX\data\users\actives\XXXXXX</value>
</add-value>
</modify-attr>
<operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=XXXXXX,OU=Usuarios XXXXc,DC=XXXX,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\XXXXX" AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" AccountTracking-sAMAccountName="XXXXX" AccountTracking-userPrincipalName="XXXX@XXXXX.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=XXXX,OU=actives">
<password-subscribe-status>
<association/>
</password-subscribe-status>
<entitlement-impl id="" name="Group" qualified-src-dn="O=data\OU=users\OU=actives\CN=XXXXXX" src="UA" src-dn="\XXXX\data\users\actives\XXXX" src-entry-id="256190" state="1">{"ID":"19d7d87749815c4bb6182a3293db8d63","ID2":"CN=All SO,OU=Grupos,DC=XXXX,DC=local"}</entitlement-impl>
</operation-data>
</modify>
</input>
</nds>


[11/19/21 19:14:23.448]:Active Directory Driver ST: Submitting document to subscriber shim:
[11/19/21 19:14:23.448]:Active Directory Driver ST:
<nds dtdversion="4.0" ndsversion="8.x">
<source>
<product edition="Advanced" version="4.8.3.1">DirXML</product>
<contact>NetIQ Corporation</contact>
</source>
<input>
<modify class-name="group" event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128">
<association>19d7d87749815c4bb6182a3293db8d63</association>
<modify-attr attr-name="member">
<add-value>
<value association-ref="1600fb61f1f4af4d93d4da4ba4cb15a2" type="dn">\SMU\data\users\actives\bXXX</value>
</add-value>
</modify-attr>
<operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=XXXX,OU=Usuarios XXX,DC=XXX,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\XXX" AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" AccountTracking-sAMAccountName="bXXX" AccountTracking-userPrincipalName="XXX@XXXX.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=XXX,OU=actives">
<password-subscribe-status>
<association/>
</password-subscribe-status>
<entitlement-impl id="" name="Group" qualified-src-dn="O=data\OU=users\OU=actives\CN=XXX" src="UA" src-dn="\SMU\data\users\actives\XXXX" src-entry-id="256190" state="1">{"ID":"19d7d87749815c4bb6182a3293db8d63","ID2":"CN=All SO,OU=Grupos,DC=XXXX,DC=local"}</entitlement-impl>
</operation-data>
</modify>
</input>
</nds>

--------

Could you help me to understand what is happening?
Thanks

Parents
  • The mailnickname is complaining it cannot find the Source DN in the <add-assocation> document.  Can you paste more of the trace, and use the Insert menu bottom of this edit box, and select Code and paste it into there.    We need to see the incoming XDS. 

  • My apologize

    [11/19/21 19:14:21.853]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20191128_120000" instance="\SMU\system\driverset1\Active Directory Driver" version="4.1.3.0">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <add-association dest-dn="\SMU\data\users\actives\bgongora" dest-entry-id="256190" event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128">1600fb61f1f4af4d93d4da4ba4cb15a2<operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\bgongora" AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" AccountTracking-sAMAccountName="bgongora" AccountTracking-userPrincipalName="bgongora@unimarc.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=bgongora,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
          </operation-data>
        </add-association>
        <status event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128" level="success">
          <operation-data AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=bgongora,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
          </operation-data>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:21.869]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:21.916]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADENTEX-itp-EntitlementsImpl%-C.
    [11/19/21 19:14:21.932]:Active Directory Driver PT:    Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
    [11/19/21 19:14:21.932]:Active Directory Driver ST:  Applying to add-association #1.
    [11/19/21 19:14:21.932]:Active Directory Driver PT:      (if-op-attr 'lockoutTime' available) = FALSE.
    [11/19/21 19:14:21.932]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Intercept ADDomain (tagged identity query) query response'.
    [11/19/21 19:14:21.932]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:21.947]:Active Directory Driver ST:      (if-operation equal "instance") = FALSE.
    [11/19/21 19:14:21.947]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
    [11/19/21 19:14:21.947]:Active Directory Driver ST:    Rule rejected.
    [11/19/21 19:14:21.963]:Active Directory Driver PT:      (if-operation equal "add") = FALSE.
    [11/19/21 19:14:21.963]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:21.963]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Intercept ADDomain (tagged identity query) query status'.
    [11/19/21 19:14:21.963]:Active Directory Driver PT:    Evaluating selection criteria for rule 'update Active Directory logon name'.
    [11/19/21 19:14:21.963]:Active Directory Driver ST:      (if-xpath true "../status[@event-id='query-driver-ident']/operation-data/@UserAccountEntitlementQuery") = FALSE.
    [11/19/21 19:14:21.978]:Active Directory Driver PT:      (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
    [11/19/21 19:14:21.978]:Active Directory Driver ST:    Rule rejected.
    [11/19/21 19:14:21.978]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:21.978]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Check target of add-association for group membership entitlements'.
    [11/19/21 19:14:21.978]:Active Directory Driver PT:Policy returned:
    [11/19/21 19:14:21.994]:Active Directory Driver ST:      (if-global-variable 'drv.entitlement.Group' equal "true") = TRUE.
    [11/19/21 19:14:21.994]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##17d3a42b230##0" level="warning">Code(-8019) Operation vetoed on unassociated object.<application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local(data\users\actives\ecampos)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:21.994]:Active Directory Driver ST:      (if-operation equal "add-association") = TRUE.
    [11/19/21 19:14:22.010]:Active Directory Driver PT:Applying policy: %+C%14CNOVLADDCFG-otp-ExchangeEntitlementQuery%-C.
    [11/19/21 19:14:22.010]:Active Directory Driver ST:      (if-op-property 'check-group-entitlements' equal "true") = TRUE.
    [11/19/21 19:14:22.025]:Active Directory Driver ST:      Query from policy
    [11/19/21 19:14:22.025]:Active Directory Driver ST:      
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query dest-dn="\SMU\data\users\actives\bgongora" dest-entry-id="256190" scope="entry">
          <read-attr attr-name="DirXML-EntitlementRef"/>
        </query>
      </input>
    </nds>

    I dont understand why on status event appears: "data\users\actives\ecampos" while DN of user is:

    "data\users\actives\bgongora"

    <status event-id="Active Directory Driver##17d3a42b230##0" level="warning">Code(-8019) Operation vetoed on unassociated object.<application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local(data\users\actives\ecampos)</object-dn>
          <component>Publisher</component>
    </status>

    Finally i wanna mention that i did tests on DEV lab and it works fine:

    [11/24/21 16:44:04.494]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20180125_120000" instance="\SMU\system\driverset1\Active Directory Driver" version="4.1.2.0">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <add-association dest-dn="\SMU\data\users\actives\zleon" dest-entry-id="55613" event-id="idm#20211124194359#1#4:c0370868-3d45-462d-9e55-680837c0453d">90469888563cb146bc69967916db88c
    f<operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=Zulia Yumajaira Leon Pi
    rela,OU=Usuarios Unimarc,DC=smu,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\zleon" AccountTracking-Operation="add" AccountTracking-association="90469888563cb146bc6996791
    6db88cf" AccountTracking-sAMAccountName="zleon" AccountTracking-userPrincipalName="zleon@smu.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" unmatched-src-dn="CN=z
    leon,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
          </operation-data>
        </add-association>
        <status event-id="idm#20211124194359#1#4:c0370868-3d45-462d-9e55-680837c0453d" level="success">
          <operation-data AccountTracking-Operation="add" AccountTracking-association="90469888563cb146bc69967916db88cf" attempt-to-match="true" check-exch-mailbox-entitlements="true" unmat
    ched-src-dn="CN=zleon,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
          </operation-data>
        </status>
      </output>
    </nds>
    [11/24/21 16:44:04.503]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADENTEX-itp-EntitlementsImpl%-C.
    [11/24/21 16:44:04.503]:Active Directory Driver ST:  Applying to add-association #1.
    [11/24/21 16:44:04.504]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Intercept ADDomain (tagged identity query) query response'.
    [11/24/21 16:44:04.504]:Active Directory Driver ST:      (if-operation equal "instance") = FALSE.
    [11/24/21 16:44:04.505]:Active Directory Driver ST:    Rule rejected.
    [11/24/21 16:44:04.505]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Intercept ADDomain (tagged identity query) query status'.
    [11/24/21 16:44:04.506]:Active Directory Driver ST:      (if-xpath true "../status[@event-id='query-driver-ident']/operation-data/@UserAccountEntitlementQuery") = FALSE.
    [11/24/21 16:44:04.507]:Active Directory Driver ST:    Rule rejected.
    [11/24/21 16:44:04.507]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Check target of add-association for group membership entitlements'.
    [11/24/21 16:44:04.509]:Active Directory Driver ST:      (if-global-variable 'drv.entitlement.Group' equal "true") = TRUE.
    [11/24/21 16:44:04.509]:Active Directory Driver ST:      (if-operation equal "add-association") = TRUE.
    [11/24/21 16:44:04.510]:Active Directory Driver ST:      (if-op-property 'check-group-entitlements' equal "true") = FALSE.
    [11/24/21 16:44:04.511]:Active Directory Driver ST:    Rule rejected.
    [11/24/21 16:44:04.511]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Check target of add-association for Exchange mailbox entitlements'.
    [11/24/21 16:44:04.512]:Active Directory Driver ST:      (if-global-variable 'drv.exchMailboxMethod' equal "entitlement") = TRUE.
    [11/24/21 16:44:04.512]:Active Directory Driver ST:      (if-operation equal "add-association") = TRUE.
    [11/24/21 16:44:04.513]:Active Directory Driver ST:      (if-op-property 'check-exch-mailbox-entitlements' equal "true") = TRUE.
    [11/24/21 16:44:04.513]:Active Directory Driver ST:      Query from policy
    [11/24/21 16:44:04.514]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query dest-dn="\SMU\data\users\actives\zleon" dest-entry-id="55613" scope="entry">
          <read-attr attr-name="DirXML-EntitlementRef"/>
        </query>
      </input>
    </nds>
    [11/24/21 16:44:04.516]:Active Directory Driver ST:      Pumping XDS to eDirectory.
    [11/24/21 16:44:04.516]:Active Directory Driver ST:      Performing operation query for \SMU\data\users\actives\zleon.
    [11/24/21 16:44:04.517]:Active Directory Driver ST:      --JCLNT-- \SMU\system\driverset1\Active Directory Driver : Duplicating : context = 137625799, tempContext = 137625686
    [11/24/21 16:44:04.519]:Active Directory Driver ST:      --JCLNT-- \SMU\system\driverset1\Active Directory Driver : Calling free on tempContext = 137625686
    [11/24/21 16:44:04.520]:Active Directory Driver ST:      Query from policy result
    [11/24/21 16:44:04.520]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
     <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <instance class-name="User" qualified-src-dn="O=data\OU=users\OU=actives\CN=zleon" src-dn="\SMU\data\users\actives\zleon" src-entry-id="55613">
          <attr attr-name="DirXML-EntitlementRef">
            <value timestamp="1637782621#25" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\ExchangeMailbox</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local"}</param>
    </ref>
              </component>
            </value>
            <value timestamp="1637783039#67" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\UserAccount</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"smu.local"}</param>
    </ref>
              </component>
            </value>
          </attr>
        </instance>
        <status level="success"></status>
      </output>
    </nds>
    [11/24/21 16:44:04.527]:Active Directory Driver ST:      (if-entitlement 'ExchangeMailbox' available) = TRUE.
    [11/24/21 16:44:04.528]:Active Directory Driver ST:    Rule selected.
    [11/24/21 16:44:04.528]:Active Directory Driver ST:    Applying rule 'Check target of add-association for Exchange mailbox entitlements'.
    [11/24/21 16:44:04.530]:Active Directory Driver ST:      Action: do-for-each(arg-node-set(token-entitlement("ExchangeMailbox"))).
    [11/24/21 16:44:04.531]:Active Directory Driver ST:        arg-node-set(token-entitlement("ExchangeMailbox"))
    [11/24/21 16:44:04.531]:Active Directory Driver ST:          token-entitlement("ExchangeMailbox")
    [11/24/21 16:44:04.532]:Active Directory Driver ST:          Token Value: {<entitlement-impl> @id = "" @name = "ExchangeMailbox" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=zleon" @src = "UA" @src-dn = "\SMU\data\users\actives\zleon" @src-entry-id = "55613" @state = "1"}.
    [11/24/21 16:44:04.533]:Active Directory Driver ST:          Arg Value: {<entitlement-impl> @id = "" @name = "ExchangeMailbox" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=zleon" @src = "UA" @src-dn = "\SMU\data\users\actives\zleon" @src-entry-id = "55613" @state = "1"}.
    [11/24/21 16:44:04.535]:Active Directory Driver ST:        Performing actions for local-variable(current-node) = <entitlement-impl> @id = "" @name = "ExchangeMailbox" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=zleon" @src = "UA" @src-dn = "\SMU\data\users\actives\zleon" @src-entry-id = "55613" @state = "1".
    [11/24/21 16:44:04.537]:Active Directory Driver ST:          Action: do-set-local-variable("homeMDB",scope="policy",token-xpath("es:getEntParamField($current-node,'ID')")).
    [11/24/21 16:44:04.538]:Active Directory Driver ST:            arg-string(token-xpath("es:getEntParamField($current-node,'ID')"))
    [11/24/21 16:44:04.539]:Active Directory Driver ST:              token-xpath("es:getEntParamField($current-node,'ID')")
    [11/24/21 16:44:04.540]:Active Directory Driver ST:                Token Value: "CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local".
    [11/24/21 16:44:04.542]:Active Directory Driver ST:              Arg Value: "CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local".
    [11/24/21 16:44:04.543]:Active Directory Driver ST:          Action: do-set-src-attr-value("homeMDB",arg-association(token-xpath("./text()")),token-local-variable("homeMDB")).
    [11/24/21 16:44:04.544]:Active Directory Driver ST:            arg-association(token-xpath("./text()"))
    [11/24/21 16:44:04.545]:Active Directory Driver ST:              token-xpath("./text()")
    [11/24/21 16:44:04.546]:Active Directory Driver ST:                Token Value: "90469888563cb146bc69967916db88cf".
    [11/24/21 16:44:04.546]:Active Directory Driver ST:              Arg Value: "90469888563cb146bc69967916db88cf".
    [11/24/21 16:44:04.547]:Active Directory Driver ST:            arg-string(token-local-variable("homeMDB"))
    [11/24/21 16:44:04.548]:Active Directory Driver ST:              token-local-variable("homeMDB")
    [11/24/21 16:44:04.548]:Active Directory Driver ST:                Token Value: "CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local".
    [11/24/21 16:44:04.550]:Active Directory Driver ST:              Arg Value: "CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local".
    [11/24/21 16:44:04.551]:Active Directory Driver ST:          Action: do-set-src-attr-value("mailNickname",arg-association(token-xpath("./text()")),token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name()))).
    [11/24/21 16:44:04.553]:Active Directory Driver ST:            arg-association(token-xpath("./text()"))
    [11/24/21 16:44:04.554]:Active Directory Driver ST:              token-xpath("./text()")
    [11/24/21 16:44:04.554]:Active Directory Driver ST:                Token Value: "90469888563cb146bc69967916db88cf".
    [11/24/21 16:44:04.555]:Active Directory Driver ST:              Arg Value: "90469888563cb146bc69967916db88cf".
    [11/24/21 16:44:04.556]:Active Directory Driver ST:            arg-string(token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name())))
    [11/24/21 16:44:04.557]:Active Directory Driver ST:              token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name()))
    [11/24/21 16:44:04.559]:Active Directory Driver ST:                token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name()))
    [11/24/21 16:44:04.560]:Active Directory Driver ST:                  token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name())
    [11/24/21 16:44:04.561]:Active Directory Driver ST:                    token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name())
    [11/24/21 16:44:04.562]:Active Directory Driver ST:                      token-src-name()
    [11/24/21 16:44:04.563]:Active Directory Driver ST:                        Token Value: "".
    [11/24/21 16:44:04.563]:Active Directory Driver ST:                      Arg Value: "".
    [11/24/21 16:44:04.564]:Active Directory Driver ST:                    Token Value: "".
    [11/24/21 16:44:04.564]:Active Directory Driver ST:                  Arg Value: "".
    [11/24/21 16:44:04.564]:Active Directory Driver ST:                Token Value: "".
    [11/24/21 16:44:04.565]:Active Directory Driver ST:              Arg Value: "".
    [11/24/21 16:44:04.565]:Active Directory Driver ST:  Direct command from policy
    [11/24/21 16:44:04.566]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify event-id="idm#20211124194359#1#4:c0370868-3d45-462d-9e55-680837c0453d">
          <association>90469888563cb146bc69967916db88cf</association>
          <modify-attr attr-name="homeMDB">
            <remove-all-values/>
            <add-value>
              <value type="string">CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="mailNickname">
          <remove-all-values/>
            <add-value>
              <value type="string"/>
            </add-value>
          </modify-attr>
          <operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=Zulia Yumajaira Leon Pirela,OU=Usuarios Unimarc,DC=smu,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\zleon" AccountTracking-Operation="add" AccountTracking-association="90469888563cb146bc69967916db88cf" AccountTracking-sAMAccountName="zleon" AccountTracking-userPrincipalName="zleon@smu.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" unmatched-src-dn="CN=zleon,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
            <entitlement-impl id="" name="ExchangeMailbox" qualified-src-dn="O=data\OU=users\OU=actives\CN=zleon" src="UA" src-dn="\SMU\data\users\actives\zleon" src-entry-id="55613" state="1">{"ID":"CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local"}</entitlement-impl>
          </operation-data>
        </modify>
      </input>
    </nds>
    [11/24/21 16:44:04.576]:Active Directory Driver ST:  Submitting document to subscriber shim:
    
    
    

Reply
  • My apologize

    [11/19/21 19:14:21.853]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20191128_120000" instance="\SMU\system\driverset1\Active Directory Driver" version="4.1.3.0">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <add-association dest-dn="\SMU\data\users\actives\bgongora" dest-entry-id="256190" event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128">1600fb61f1f4af4d93d4da4ba4cb15a2<operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\bgongora" AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" AccountTracking-sAMAccountName="bgongora" AccountTracking-userPrincipalName="bgongora@unimarc.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=bgongora,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
          </operation-data>
        </add-association>
        <status event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128" level="success">
          <operation-data AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=bgongora,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
          </operation-data>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:21.869]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:21.916]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADENTEX-itp-EntitlementsImpl%-C.
    [11/19/21 19:14:21.932]:Active Directory Driver PT:    Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
    [11/19/21 19:14:21.932]:Active Directory Driver ST:  Applying to add-association #1.
    [11/19/21 19:14:21.932]:Active Directory Driver PT:      (if-op-attr 'lockoutTime' available) = FALSE.
    [11/19/21 19:14:21.932]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Intercept ADDomain (tagged identity query) query response'.
    [11/19/21 19:14:21.932]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:21.947]:Active Directory Driver ST:      (if-operation equal "instance") = FALSE.
    [11/19/21 19:14:21.947]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
    [11/19/21 19:14:21.947]:Active Directory Driver ST:    Rule rejected.
    [11/19/21 19:14:21.963]:Active Directory Driver PT:      (if-operation equal "add") = FALSE.
    [11/19/21 19:14:21.963]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:21.963]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Intercept ADDomain (tagged identity query) query status'.
    [11/19/21 19:14:21.963]:Active Directory Driver PT:    Evaluating selection criteria for rule 'update Active Directory logon name'.
    [11/19/21 19:14:21.963]:Active Directory Driver ST:      (if-xpath true "../status[@event-id='query-driver-ident']/operation-data/@UserAccountEntitlementQuery") = FALSE.
    [11/19/21 19:14:21.978]:Active Directory Driver PT:      (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
    [11/19/21 19:14:21.978]:Active Directory Driver ST:    Rule rejected.
    [11/19/21 19:14:21.978]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:21.978]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Check target of add-association for group membership entitlements'.
    [11/19/21 19:14:21.978]:Active Directory Driver PT:Policy returned:
    [11/19/21 19:14:21.994]:Active Directory Driver ST:      (if-global-variable 'drv.entitlement.Group' equal "true") = TRUE.
    [11/19/21 19:14:21.994]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##17d3a42b230##0" level="warning">Code(-8019) Operation vetoed on unassociated object.<application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local(data\users\actives\ecampos)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:21.994]:Active Directory Driver ST:      (if-operation equal "add-association") = TRUE.
    [11/19/21 19:14:22.010]:Active Directory Driver PT:Applying policy: %+C%14CNOVLADDCFG-otp-ExchangeEntitlementQuery%-C.
    [11/19/21 19:14:22.010]:Active Directory Driver ST:      (if-op-property 'check-group-entitlements' equal "true") = TRUE.
    [11/19/21 19:14:22.025]:Active Directory Driver ST:      Query from policy
    [11/19/21 19:14:22.025]:Active Directory Driver ST:      
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query dest-dn="\SMU\data\users\actives\bgongora" dest-entry-id="256190" scope="entry">
          <read-attr attr-name="DirXML-EntitlementRef"/>
        </query>
      </input>
    </nds>

    I dont understand why on status event appears: "data\users\actives\ecampos" while DN of user is:

    "data\users\actives\bgongora"

    <status event-id="Active Directory Driver##17d3a42b230##0" level="warning">Code(-8019) Operation vetoed on unassociated object.<application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local(data\users\actives\ecampos)</object-dn>
          <component>Publisher</component>
    </status>

    Finally i wanna mention that i did tests on DEV lab and it works fine:

    [11/24/21 16:44:04.494]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20180125_120000" instance="\SMU\system\driverset1\Active Directory Driver" version="4.1.2.0">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <add-association dest-dn="\SMU\data\users\actives\zleon" dest-entry-id="55613" event-id="idm#20211124194359#1#4:c0370868-3d45-462d-9e55-680837c0453d">90469888563cb146bc69967916db88c
    f<operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=Zulia Yumajaira Leon Pi
    rela,OU=Usuarios Unimarc,DC=smu,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\zleon" AccountTracking-Operation="add" AccountTracking-association="90469888563cb146bc6996791
    6db88cf" AccountTracking-sAMAccountName="zleon" AccountTracking-userPrincipalName="zleon@smu.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" unmatched-src-dn="CN=z
    leon,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
          </operation-data>
        </add-association>
        <status event-id="idm#20211124194359#1#4:c0370868-3d45-462d-9e55-680837c0453d" level="success">
          <operation-data AccountTracking-Operation="add" AccountTracking-association="90469888563cb146bc69967916db88cf" attempt-to-match="true" check-exch-mailbox-entitlements="true" unmat
    ched-src-dn="CN=zleon,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
          </operation-data>
        </status>
      </output>
    </nds>
    [11/24/21 16:44:04.503]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADENTEX-itp-EntitlementsImpl%-C.
    [11/24/21 16:44:04.503]:Active Directory Driver ST:  Applying to add-association #1.
    [11/24/21 16:44:04.504]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Intercept ADDomain (tagged identity query) query response'.
    [11/24/21 16:44:04.504]:Active Directory Driver ST:      (if-operation equal "instance") = FALSE.
    [11/24/21 16:44:04.505]:Active Directory Driver ST:    Rule rejected.
    [11/24/21 16:44:04.505]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Intercept ADDomain (tagged identity query) query status'.
    [11/24/21 16:44:04.506]:Active Directory Driver ST:      (if-xpath true "../status[@event-id='query-driver-ident']/operation-data/@UserAccountEntitlementQuery") = FALSE.
    [11/24/21 16:44:04.507]:Active Directory Driver ST:    Rule rejected.
    [11/24/21 16:44:04.507]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Check target of add-association for group membership entitlements'.
    [11/24/21 16:44:04.509]:Active Directory Driver ST:      (if-global-variable 'drv.entitlement.Group' equal "true") = TRUE.
    [11/24/21 16:44:04.509]:Active Directory Driver ST:      (if-operation equal "add-association") = TRUE.
    [11/24/21 16:44:04.510]:Active Directory Driver ST:      (if-op-property 'check-group-entitlements' equal "true") = FALSE.
    [11/24/21 16:44:04.511]:Active Directory Driver ST:    Rule rejected.
    [11/24/21 16:44:04.511]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Check target of add-association for Exchange mailbox entitlements'.
    [11/24/21 16:44:04.512]:Active Directory Driver ST:      (if-global-variable 'drv.exchMailboxMethod' equal "entitlement") = TRUE.
    [11/24/21 16:44:04.512]:Active Directory Driver ST:      (if-operation equal "add-association") = TRUE.
    [11/24/21 16:44:04.513]:Active Directory Driver ST:      (if-op-property 'check-exch-mailbox-entitlements' equal "true") = TRUE.
    [11/24/21 16:44:04.513]:Active Directory Driver ST:      Query from policy
    [11/24/21 16:44:04.514]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query dest-dn="\SMU\data\users\actives\zleon" dest-entry-id="55613" scope="entry">
          <read-attr attr-name="DirXML-EntitlementRef"/>
        </query>
      </input>
    </nds>
    [11/24/21 16:44:04.516]:Active Directory Driver ST:      Pumping XDS to eDirectory.
    [11/24/21 16:44:04.516]:Active Directory Driver ST:      Performing operation query for \SMU\data\users\actives\zleon.
    [11/24/21 16:44:04.517]:Active Directory Driver ST:      --JCLNT-- \SMU\system\driverset1\Active Directory Driver : Duplicating : context = 137625799, tempContext = 137625686
    [11/24/21 16:44:04.519]:Active Directory Driver ST:      --JCLNT-- \SMU\system\driverset1\Active Directory Driver : Calling free on tempContext = 137625686
    [11/24/21 16:44:04.520]:Active Directory Driver ST:      Query from policy result
    [11/24/21 16:44:04.520]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
     <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <instance class-name="User" qualified-src-dn="O=data\OU=users\OU=actives\CN=zleon" src-dn="\SMU\data\users\actives\zleon" src-entry-id="55613">
          <attr attr-name="DirXML-EntitlementRef">
            <value timestamp="1637782621#25" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\ExchangeMailbox</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local"}</param>
    </ref>
              </component>
            </value>
            <value timestamp="1637783039#67" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\UserAccount</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"smu.local"}</param>
    </ref>
              </component>
            </value>
          </attr>
        </instance>
        <status level="success"></status>
      </output>
    </nds>
    [11/24/21 16:44:04.527]:Active Directory Driver ST:      (if-entitlement 'ExchangeMailbox' available) = TRUE.
    [11/24/21 16:44:04.528]:Active Directory Driver ST:    Rule selected.
    [11/24/21 16:44:04.528]:Active Directory Driver ST:    Applying rule 'Check target of add-association for Exchange mailbox entitlements'.
    [11/24/21 16:44:04.530]:Active Directory Driver ST:      Action: do-for-each(arg-node-set(token-entitlement("ExchangeMailbox"))).
    [11/24/21 16:44:04.531]:Active Directory Driver ST:        arg-node-set(token-entitlement("ExchangeMailbox"))
    [11/24/21 16:44:04.531]:Active Directory Driver ST:          token-entitlement("ExchangeMailbox")
    [11/24/21 16:44:04.532]:Active Directory Driver ST:          Token Value: {<entitlement-impl> @id = "" @name = "ExchangeMailbox" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=zleon" @src = "UA" @src-dn = "\SMU\data\users\actives\zleon" @src-entry-id = "55613" @state = "1"}.
    [11/24/21 16:44:04.533]:Active Directory Driver ST:          Arg Value: {<entitlement-impl> @id = "" @name = "ExchangeMailbox" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=zleon" @src = "UA" @src-dn = "\SMU\data\users\actives\zleon" @src-entry-id = "55613" @state = "1"}.
    [11/24/21 16:44:04.535]:Active Directory Driver ST:        Performing actions for local-variable(current-node) = <entitlement-impl> @id = "" @name = "ExchangeMailbox" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=zleon" @src = "UA" @src-dn = "\SMU\data\users\actives\zleon" @src-entry-id = "55613" @state = "1".
    [11/24/21 16:44:04.537]:Active Directory Driver ST:          Action: do-set-local-variable("homeMDB",scope="policy",token-xpath("es:getEntParamField($current-node,'ID')")).
    [11/24/21 16:44:04.538]:Active Directory Driver ST:            arg-string(token-xpath("es:getEntParamField($current-node,'ID')"))
    [11/24/21 16:44:04.539]:Active Directory Driver ST:              token-xpath("es:getEntParamField($current-node,'ID')")
    [11/24/21 16:44:04.540]:Active Directory Driver ST:                Token Value: "CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local".
    [11/24/21 16:44:04.542]:Active Directory Driver ST:              Arg Value: "CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local".
    [11/24/21 16:44:04.543]:Active Directory Driver ST:          Action: do-set-src-attr-value("homeMDB",arg-association(token-xpath("./text()")),token-local-variable("homeMDB")).
    [11/24/21 16:44:04.544]:Active Directory Driver ST:            arg-association(token-xpath("./text()"))
    [11/24/21 16:44:04.545]:Active Directory Driver ST:              token-xpath("./text()")
    [11/24/21 16:44:04.546]:Active Directory Driver ST:                Token Value: "90469888563cb146bc69967916db88cf".
    [11/24/21 16:44:04.546]:Active Directory Driver ST:              Arg Value: "90469888563cb146bc69967916db88cf".
    [11/24/21 16:44:04.547]:Active Directory Driver ST:            arg-string(token-local-variable("homeMDB"))
    [11/24/21 16:44:04.548]:Active Directory Driver ST:              token-local-variable("homeMDB")
    [11/24/21 16:44:04.548]:Active Directory Driver ST:                Token Value: "CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local".
    [11/24/21 16:44:04.550]:Active Directory Driver ST:              Arg Value: "CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local".
    [11/24/21 16:44:04.551]:Active Directory Driver ST:          Action: do-set-src-attr-value("mailNickname",arg-association(token-xpath("./text()")),token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name()))).
    [11/24/21 16:44:04.553]:Active Directory Driver ST:            arg-association(token-xpath("./text()"))
    [11/24/21 16:44:04.554]:Active Directory Driver ST:              token-xpath("./text()")
    [11/24/21 16:44:04.554]:Active Directory Driver ST:                Token Value: "90469888563cb146bc69967916db88cf".
    [11/24/21 16:44:04.555]:Active Directory Driver ST:              Arg Value: "90469888563cb146bc69967916db88cf".
    [11/24/21 16:44:04.556]:Active Directory Driver ST:            arg-string(token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name())))
    [11/24/21 16:44:04.557]:Active Directory Driver ST:              token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name()))
    [11/24/21 16:44:04.559]:Active Directory Driver ST:                token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name()))
    [11/24/21 16:44:04.560]:Active Directory Driver ST:                  token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name())
    [11/24/21 16:44:04.561]:Active Directory Driver ST:                    token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name())
    [11/24/21 16:44:04.562]:Active Directory Driver ST:                      token-src-name()
    [11/24/21 16:44:04.563]:Active Directory Driver ST:                        Token Value: "".
    [11/24/21 16:44:04.563]:Active Directory Driver ST:                      Arg Value: "".
    [11/24/21 16:44:04.564]:Active Directory Driver ST:                    Token Value: "".
    [11/24/21 16:44:04.564]:Active Directory Driver ST:                  Arg Value: "".
    [11/24/21 16:44:04.564]:Active Directory Driver ST:                Token Value: "".
    [11/24/21 16:44:04.565]:Active Directory Driver ST:              Arg Value: "".
    [11/24/21 16:44:04.565]:Active Directory Driver ST:  Direct command from policy
    [11/24/21 16:44:04.566]:Active Directory Driver ST:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify event-id="idm#20211124194359#1#4:c0370868-3d45-462d-9e55-680837c0453d">
          <association>90469888563cb146bc69967916db88cf</association>
          <modify-attr attr-name="homeMDB">
            <remove-all-values/>
            <add-value>
              <value type="string">CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="mailNickname">
          <remove-all-values/>
            <add-value>
              <value type="string"/>
            </add-value>
          </modify-attr>
          <operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=Zulia Yumajaira Leon Pirela,OU=Usuarios Unimarc,DC=smu,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\zleon" AccountTracking-Operation="add" AccountTracking-association="90469888563cb146bc69967916db88cf" AccountTracking-sAMAccountName="zleon" AccountTracking-userPrincipalName="zleon@smu.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" unmatched-src-dn="CN=zleon,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
            <entitlement-impl id="" name="ExchangeMailbox" qualified-src-dn="O=data\OU=users\OU=actives\CN=zleon" src="UA" src-dn="\SMU\data\users\actives\zleon" src-entry-id="55613" state="1">{"ID":"CN=Mailbox Database 0125909999,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=SMU,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=smu,DC=local"}</entitlement-impl>
          </operation-data>
        </modify>
      </input>
    </nds>
    [11/24/21 16:44:04.576]:Active Directory Driver ST:  Submitting document to subscriber shim:
    
    
    

Children
  • Your first code snippet is showing an interleaved Sub/Pub event. So it is much harder to read.  This is why the second code snippet isshowing the wrong object.  There are two different events on two different channels interwoven.

    And in the first snippet you do not show enough further detail to see what happens. It ends with a query for the Entitlement data on the user to see which groups and Exchange entitlements they have.  But you cut it off at the query and we do not see the response nor the processing.

  • Verified Answer

    Good morning. How are you? I hope that very good.

    Here is the complete log:

    [11/19/21 19:14:21.853]:Active Directory Driver ST:
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20191128_120000" instance="\SMU\system\driverset1\Active Directory Driver" version="4.1.3.0">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <add-association dest-dn="\SMU\data\users\actives\bgongora" dest-entry-id="256190" event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128">1600fb61f1f4af4d93d4da4ba4cb15a2<operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\bgongora" AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" AccountTracking-sAMAccountName="bgongora" AccountTracking-userPrincipalName="bgongora@unimarc.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=bgongora,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
          </operation-data>
        </add-association>
        <status event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128" level="success">
          <operation-data AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=bgongora,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
          </operation-data>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:21.869]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:21.916]:Active Directory Driver ST:Applying policy: %+C%14CNOVLADENTEX-itp-EntitlementsImpl%-C.
    [11/19/21 19:14:21.932]:Active Directory Driver PT:    Evaluating selection criteria for rule 'lockoutTime: Convert to Active Directory form'.
    [11/19/21 19:14:21.932]:Active Directory Driver ST:  Applying to add-association #1.
    [11/19/21 19:14:21.932]:Active Directory Driver PT:      (if-op-attr 'lockoutTime' available) = FALSE.
    [11/19/21 19:14:21.932]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Intercept ADDomain (tagged identity query) query response'.
    [11/19/21 19:14:21.932]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:21.947]:Active Directory Driver ST:      (if-operation equal "instance") = FALSE.
    [11/19/21 19:14:21.947]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Add: User - convert multi-valued Telephone to single value'.
    [11/19/21 19:14:21.947]:Active Directory Driver ST:    Rule rejected.
    [11/19/21 19:14:21.963]:Active Directory Driver PT:      (if-operation equal "add") = FALSE.
    [11/19/21 19:14:21.963]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:21.963]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Intercept ADDomain (tagged identity query) query status'.
    [11/19/21 19:14:21.963]:Active Directory Driver PT:    Evaluating selection criteria for rule 'update Active Directory logon name'.
    [11/19/21 19:14:21.963]:Active Directory Driver ST:      (if-xpath true "../status[@event-id='query-driver-ident']/operation-data/@UserAccountEntitlementQuery") = FALSE.
    [11/19/21 19:14:21.978]:Active Directory Driver PT:      (if-xpath true "self::status[@level = 'success']/operation-data/windows-2000-logon-name") = FALSE.
    [11/19/21 19:14:21.978]:Active Directory Driver ST:    Rule rejected.
    [11/19/21 19:14:21.978]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:21.978]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Check target of add-association for group membership entitlements'.
    [11/19/21 19:14:21.978]:Active Directory Driver PT:Policy returned:
    [11/19/21 19:14:21.994]:Active Directory Driver ST:      (if-global-variable 'drv.entitlement.Group' equal "true") = TRUE.
    [11/19/21 19:14:21.994]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##17d3a42b230##0" level="warning">Code(-8019) Operation vetoed on unassociated object.<application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local(data\users\actives\ecampos)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:21.994]:Active Directory Driver ST:      (if-operation equal "add-association") = TRUE.
    [11/19/21 19:14:22.010]:Active Directory Driver PT:Applying policy: %+C%14CNOVLADDCFG-otp-ExchangeEntitlementQuery%-C.
    [11/19/21 19:14:22.010]:Active Directory Driver ST:      (if-op-property 'check-group-entitlements' equal "true") = TRUE.
    [11/19/21 19:14:22.025]:Active Directory Driver ST:      Query from policy
    [11/19/21 19:14:22.025]:Active Directory Driver ST:      
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <query dest-dn="\SMU\data\users\actives\bgongora" dest-entry-id="256190" scope="entry">
          <read-attr attr-name="DirXML-EntitlementRef"/>
        </query>
      </input>
    </nds>
    [11/19/21 19:14:22.025]:Active Directory Driver PT:  Applying to status #1.
    [11/19/21 19:14:22.041]:Active Directory Driver ST:      Pumping XDS to eDirectory.
    [11/19/21 19:14:22.041]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Add dest-dn to the Exchange Entitlement Query'.
    [11/19/21 19:14:22.041]:Active Directory Driver ST:      Performing operation query for \SMU\data\users\actives\bgongora.
    [11/19/21 19:14:22.041]:Active Directory Driver PT:      (if-operation equal "query") = FALSE.
    [11/19/21 19:14:22.041]:Active Directory Driver ST:      --JCLNT-- \SMU\system\driverset1\Active Directory Driver : Duplicating : context = 641663175, tempContext = 641663277
    [11/19/21 19:14:22.057]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:22.057]:Active Directory Driver ST:      --JCLNT-- \SMU\system\driverset1\Active Directory Driver : Calling free on tempContext = 641663277
    [11/19/21 19:14:22.057]:Active Directory Driver PT:Policy returned:
    [11/19/21 19:14:22.057]:Active Directory Driver ST:      Query from policy result
    [11/19/21 19:14:22.057]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##17d3a42b230##0" level="warning">Code(-8019) Operation vetoed on unassociated object.<application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local(data\users\actives\ecampos)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:22.088]:Active Directory Driver PT:Applying policy: %+C%14CNOVLADATRK-otp-Subscribe%-C.
    [11/19/21 19:14:22.072]:Active Directory Driver ST:      
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <instance class-name="User" qualified-src-dn="O=data\OU=users\OU=actives\CN=bgongora" src-dn="\SMU\data\users\actives\bgongora" src-entry-id="256190">
          <attr attr-name="DirXML-EntitlementRef">
            <value timestamp="1637359989#95" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\ExchangeMailbox</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"CN=New Base 60MG,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Rendic,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=rendic,DC=local"}</param>
    </ref>
              </component>
            </value>
            <value timestamp="1637359990#174" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\UserAccount</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"unimarc.local"}</param>
    </ref>
              </component>
            </value>
            <value timestamp="1637360053#342" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\Group</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"19d7d87749815c4bb6182a3293db8d63","ID2":"CN=All SO,OU=Grupos,DC=unimarc,DC=local"}</param>
    </ref>
              </component>
            </value>
            <value timestamp="1637360056#136" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\Group</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"be70972e49f2a349babd66e5891a393a","ID2":"CN=allsubscribers080e28f1,OU=Grupos,DC=unimarc,DC=local"}</param>
    </ref>
              </component>
            </value>
            <value timestamp="1637360057#106" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\Group</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"ea49f73eaf4ad14db0f81c45d6e2c828","ID2":"CN=allsubscribers507a26c2,OU=Grupos,DC=unimarc,DC=local"}</param>
    </ref>
              </component>
            </value>
            <value timestamp="1637360058#162" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\Group</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"671c6dd7b9cf5e4484fc7f3d6d1112d6","ID2":"CN=BlueCoat-Medio,OU=Grupos,DC=unimarc,DC=local"}</param>
    </ref>
              </component>
            </value>
            <value timestamp="1637360059#96" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\Group</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"bf1f74ec26ca32488e7bb34f5853bc32","ID2":"CN=Epass,OU=Grupos,DC=unimarc,DC=local"}</param>
    </ref>
              </component>
            </value>
            <value timestamp="1637360060#367" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\Group</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"95d0b40948ed9a4ea778ef41637a0a16","ID2":"CN=Proxy Bluecoat,OU=Grupos,DC=unimarc,DC=local"}</param>
    </ref>
              </component>
            </value>
            <value timestamp="1637360061#132" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\Group</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"4e542b9188116e44baab8495d8f33f45","ID2":"CN=Wifi Headquarters,OU=Grupos,DC=unimarc,DC=local"}</param>
    </ref>
              </component>
            </value>
            <value timestamp="1637360061#227" type="structured">
              <component name="nameSpace">1</component>
              <component name="volume">\SMU\system\driverset1\Active Directory Driver\Group</component>
              <component name="path.xml">
                <ref>
    <src>UA</src>
    <id/>
    <param>{"ID":"bc51f415c2a03e41b4a8b86df398fe97","ID2":"CN=Grupo Disponible 1 - Politica Masiva,OU=Grupos,DC=unimarc,DC=local"}</param>
    </ref>
              </component>
            </value>
          </attr>
        </instance>
        <status level="success"></status>
      </output>
    </nds>
    [11/19/21 19:14:22.088]:Active Directory Driver PT:  Applying to status #1.
    [11/19/21 19:14:22.260]:Active Directory Driver ST:      (if-entitlement 'Group' available) = TRUE.
    [11/19/21 19:14:22.260]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Do not process Account Tracking policies if modify with no source-dn '.
    [11/19/21 19:14:22.260]:Active Directory Driver ST:    Rule selected.
    [11/19/21 19:14:22.260]:Active Directory Driver PT:      (if-operation equal "modify") = FALSE.
    [11/19/21 19:14:22.260]:Active Directory Driver ST:    Applying rule 'Check target of add-association for group membership entitlements'.
    [11/19/21 19:14:22.260]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:22.260]:Active Directory Driver ST:      Action: do-for-each(arg-node-set(token-entitlement("Group"))).
    [11/19/21 19:14:22.260]:Active Directory Driver PT:    Evaluating selection criteria for rule 'AccountTracking - Initialize Realm Mapping'.
    [11/19/21 19:14:22.275]:Active Directory Driver ST:        arg-node-set(token-entitlement("Group"))
    [11/19/21 19:14:22.275]:Active Directory Driver PT:      (if-global-variable 'drv.acctTrk.enable' equal "true") = TRUE.
    [11/19/21 19:14:22.275]:Active Directory Driver ST:          token-entitlement("Group")
    [11/19/21 19:14:22.291]:Active Directory Driver PT:      (if-global-variable 'drv.acctTrk.mode' equal "fanout") = FALSE.
    [11/19/21 19:14:22.291]:Active Directory Driver ST:          Token Value: {<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1"}.
    [11/19/21 19:14:22.291]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:22.338]:Active Directory Driver ST:          Arg Value: {<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1",<entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1"}.
    [11/19/21 19:14:22.338]:Active Directory Driver PT:    Evaluating selection criteria for rule 'AccountTracking - disregard if disabled or wrong object class'.
    [11/19/21 19:14:22.400]:Active Directory Driver ST:        Performing actions for local-variable(current-node) = <entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1".
    [11/19/21 19:14:22.400]:Active Directory Driver PT:    Rule selected.
    [11/19/21 19:14:22.416]:Active Directory Driver ST:          Action: do-set-local-variable("group-assoc",scope="policy",token-xpath("es:getEntParamField($current-node,'ID')
    ")).
    [11/19/21 19:14:22.416]:Active Directory Driver PT:    Applying rule 'AccountTracking - disregard if disabled or wrong object class'.
    [11/19/21 19:14:22.416]:Active Directory Driver PT:      Action: do-if().
    [11/19/21 19:14:22.416]:Active Directory Driver PT:        Evaluating conditions.
    [11/19/21 19:14:22.416]:Active Directory Driver ST:            arg-string(token-xpath("es:getEntParamField($current-node,'ID')
    "))
    [11/19/21 19:14:22.432]:Active Directory Driver PT:          (if-global-variable 'drv.acctTrk.enable' not-equal "true") = FALSE.
    [11/19/21 19:14:22.432]:Active Directory Driver PT:        Performing else actions.
    [11/19/21 19:14:22.432]:Active Directory Driver PT:          Action: do-for-each(arg-node-set(token-global-variable("drv.acctTrk.objectClass"))).
    [11/19/21 19:14:22.432]:Active Directory Driver ST:              token-xpath("es:getEntParamField($current-node,'ID')
    ")
    [11/19/21 19:14:22.447]:Active Directory Driver PT:            arg-node-set(token-global-variable("drv.acctTrk.objectClass"))
    [11/19/21 19:14:22.447]:Active Directory Driver ST:                Token Value: "19d7d87749815c4bb6182a3293db8d63".
    [11/19/21 19:14:22.447]:Active Directory Driver PT:              token-global-variable("drv.acctTrk.objectClass")
    [11/19/21 19:14:22.447]:Active Directory Driver ST:              Arg Value: "19d7d87749815c4bb6182a3293db8d63".
    [11/19/21 19:14:22.463]:Active Directory Driver ST:          Action: do-add-src-attr-value("member",class-name="group",arg-association(token-local-variable("group-assoc")),token-dest-dn()).
    [11/19/21 19:14:22.463]:Active Directory Driver PT:              Token Value: {"user"}.
    [11/19/21 19:14:22.463]:Active Directory Driver ST:            arg-association(token-local-variable("group-assoc"))
    [11/19/21 19:14:22.463]:Active Directory Driver PT:              Arg Value: {"user"}.
    [11/19/21 19:14:22.478]:Active Directory Driver ST:              token-local-variable("group-assoc")
    [11/19/21 19:14:22.478]:Active Directory Driver PT:            Performing actions for local-variable(current-node) = "user".
    [11/19/21 19:14:22.478]:Active Directory Driver PT:              Action: do-if().
    [11/19/21 19:14:22.478]:Active Directory Driver ST:                Token Value: "19d7d87749815c4bb6182a3293db8d63".
    [11/19/21 19:14:22.478]:Active Directory Driver PT:                Evaluating conditions.
    [11/19/21 19:14:22.494]:Active Directory Driver ST:              Arg Value: "19d7d87749815c4bb6182a3293db8d63".
    [11/19/21 19:14:22.494]:Active Directory Driver PT:                  (if-class-name equal "$current-node$") = FALSE.
    [11/19/21 19:14:22.494]:Active Directory Driver ST:            arg-string(token-dest-dn())
    [11/19/21 19:14:22.494]:Active Directory Driver PT:                Performing else actions.
    [11/19/21 19:14:22.510]:Active Directory Driver ST:              token-dest-dn()
    [11/19/21 19:14:22.510]:Active Directory Driver ST:                Token Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:22.510]:Active Directory Driver ST:              Arg Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:22.510]:Active Directory Driver PT:          Action: do-if().
    [11/19/21 19:14:22.510]:Active Directory Driver ST:          Action: do-set-xml-attr("association-ref","../modify[last()]/modify-attr[last()]/add-value[last()]/value[last()]",token-xpath("./text()")).
    [11/19/21 19:14:22.525]:Active Directory Driver PT:            Evaluating conditions.
    [11/19/21 19:14:22.525]:Active Directory Driver ST:            arg-string(token-xpath("./text()"))
    [11/19/21 19:14:22.541]:Active Directory Driver ST:              token-xpath("./text()")
    [11/19/21 19:14:22.525]:Active Directory Driver PT:              (if-local-variable 'pass' not-available) = TRUE.
    [11/19/21 19:14:22.541]:Active Directory Driver ST:                Token Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:22.541]:Active Directory Driver PT:            Performing if actions.
    [11/19/21 19:14:22.541]:Active Directory Driver ST:              Arg Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:22.541]:Active Directory Driver PT:              Action: do-break().
    [11/19/21 19:14:22.557]:Active Directory Driver ST:        Performing actions for local-variable(current-node) = <entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1".
    [11/19/21 19:14:22.557]:Active Directory Driver PT:Policy returned:
    [11/19/21 19:14:22.557]:Active Directory Driver ST:          Action: do-set-local-variable("group-assoc",scope="policy",token-xpath("es:getEntParamField($current-node,'ID')
    ")).
    [11/19/21 19:14:22.572]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##17d3a42b230##0" level="warning">Code(-8019) Operation vetoed on unassociated object.<application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local(data\users\actives\ecampos)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:22.572]:Active Directory Driver ST:            arg-string(token-xpath("es:getEntParamField($current-node,'ID')
    "))
    [11/19/21 19:14:22.588]:Active Directory Driver PT:Applying policy: %+C%14CNOVLADENTEX-otp-EntitlementsImpl%-C.
    [11/19/21 19:14:22.588]:Active Directory Driver ST:              token-xpath("es:getEntParamField($current-node,'ID')
    ")
    [11/19/21 19:14:22.588]:Active Directory Driver PT:  Applying to status #1.
    [11/19/21 19:14:22.603]:Active Directory Driver ST:                Token Value: "be70972e49f2a349babd66e5891a393a".
    [11/19/21 19:14:22.603]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Intercept outbound queries for ADDomain'.
    [11/19/21 19:14:22.603]:Active Directory Driver ST:              Arg Value: "be70972e49f2a349babd66e5891a393a".
    [11/19/21 19:14:22.603]:Active Directory Driver PT:      (if-class-name equal "ADDomain") = FALSE.
    [11/19/21 19:14:22.603]:Active Directory Driver ST:          Action: do-add-src-attr-value("member",class-name="group",arg-association(token-local-variable("group-assoc")),token-dest-dn()).
    [11/19/21 19:14:22.619]:Active Directory Driver ST:            arg-association(token-local-variable("group-assoc"))
    [11/19/21 19:14:22.619]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:22.619]:Active Directory Driver ST:              token-local-variable("group-assoc")
    [11/19/21 19:14:22.619]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Intercept outbound queries for ADDomain with query-ex'.
    [11/19/21 19:14:22.635]:Active Directory Driver ST:                Token Value: "be70972e49f2a349babd66e5891a393a".
    [11/19/21 19:14:22.635]:Active Directory Driver PT:      (if-class-name equal "ADDomain") = FALSE.
    [11/19/21 19:14:22.635]:Active Directory Driver ST:              Arg Value: "be70972e49f2a349babd66e5891a393a".
    [11/19/21 19:14:22.635]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:22.650]:Active Directory Driver ST:            arg-string(token-dest-dn())
    [11/19/21 19:14:22.650]:Active Directory Driver PT:Policy returned:
    [11/19/21 19:14:22.650]:Active Directory Driver ST:              token-dest-dn()
    [11/19/21 19:14:22.650]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##17d3a42b230##0" level="warning">Code(-8019) Operation vetoed on unassociated object.<application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local(data\users\actives\ecampos)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:22.650]:Active Directory Driver ST:                Token Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:22.682]:Active Directory Driver PT:Applying policy: %+C%14CNOVLADENTEX-otp-ExchangeMailboxPolicy%-C.
    [11/19/21 19:14:22.682]:Active Directory Driver ST:              Arg Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:22.682]:Active Directory Driver PT:  Applying to status #1.
    [11/19/21 19:14:22.697]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Exchange: Remove HomeMDB when disabled'.
    [11/19/21 19:14:22.682]:Active Directory Driver ST:          Action: do-set-xml-attr("association-ref","../modify[last()]/modify-attr[last()]/add-value[last()]/value[last()]",token-xpath("./text()")).
    [11/19/21 19:14:22.697]:Active Directory Driver PT:      (if-global-variable 'drv.exchMailboxMethod' equal "disabled") = FALSE.
    [11/19/21 19:14:22.697]:Active Directory Driver ST:            arg-string(token-xpath("./text()"))
    [11/19/21 19:14:22.697]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:22.697]:Active Directory Driver ST:              token-xpath("./text()")
    [11/19/21 19:14:22.713]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Exchange: Check HomeMDB when enabled'.
    [11/19/21 19:14:22.713]:Active Directory Driver ST:                Token Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:22.713]:Active Directory Driver PT:      (if-class-name equal "user") = FALSE.
    [11/19/21 19:14:22.713]:Active Directory Driver ST:              Arg Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:22.713]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:22.713]:Active Directory Driver ST:        Performing actions for local-variable(current-node) = <entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1".
    [11/19/21 19:14:22.728]:Active Directory Driver PT:Policy returned:
    [11/19/21 19:14:22.728]:Active Directory Driver ST:          Action: do-set-local-variable("group-assoc",scope="policy",token-xpath("es:getEntParamField($current-node,'ID')
    ")).
    [11/19/21 19:14:22.728]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##17d3a42b230##0" level="warning">Code(-8019) Operation vetoed on unassociated object.<application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local(data\users\actives\ecampos)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:22.728]:Active Directory Driver ST:            arg-string(token-xpath("es:getEntParamField($current-node,'ID')
    "))
    [11/19/21 19:14:22.744]:Active Directory Driver PT:Applying policy: %+C%14CNOVLPWDSYNC-otp-EmailOnFailedPwdPub%-C.
    [11/19/21 19:14:22.744]:Active Directory Driver ST:              token-xpath("es:getEntParamField($current-node,'ID')
    ")
    [11/19/21 19:14:22.744]:Active Directory Driver PT:  Applying to status #1.
    [11/19/21 19:14:22.744]:Active Directory Driver ST:                Token Value: "ea49f73eaf4ad14db0f81c45d6e2c828".
    [11/19/21 19:14:22.760]:Active Directory Driver PT:    Evaluating selection criteria for rule 'Send e-mail for a failed publish password operation'.
    [11/19/21 19:14:22.760]:Active Directory Driver ST:              Arg Value: "ea49f73eaf4ad14db0f81c45d6e2c828".
    [11/19/21 19:14:22.760]:Active Directory Driver PT:      (if-global-variable 'notify-user-on-password-dist-failure' equal "true") = FALSE.
    [11/19/21 19:14:22.760]:Active Directory Driver ST:          Action: do-add-src-attr-value("member",class-name="group",arg-association(token-local-variable("group-assoc")),token-dest-dn()).
    [11/19/21 19:14:22.775]:Active Directory Driver ST:            arg-association(token-local-variable("group-assoc"))
    [11/19/21 19:14:22.775]:Active Directory Driver PT:    Rule rejected.
    [11/19/21 19:14:22.775]:Active Directory Driver ST:              token-local-variable("group-assoc")
    [11/19/21 19:14:22.775]:Active Directory Driver PT:Policy returned:
    [11/19/21 19:14:22.791]:Active Directory Driver ST:                Token Value: "ea49f73eaf4ad14db0f81c45d6e2c828".
    [11/19/21 19:14:22.791]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##17d3a42b230##0" level="warning">Code(-8019) Operation vetoed on unassociated object.<application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local(data\users\actives\ecampos)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:22.791]:Active Directory Driver ST:              Arg Value: "ea49f73eaf4ad14db0f81c45d6e2c828".
    [11/19/21 19:14:22.807]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##17d3a42b230##0" level="warning">Code(-8019) Operation vetoed on unassociated object.<application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local(data\users\actives\ecampos)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:22.822]:Active Directory Driver ST:            arg-string(token-dest-dn())
    [11/19/21 19:14:22.822]:Active Directory Driver PT:Remote Interface Driver: Sending...
    [11/19/21 19:14:22.838]:Active Directory Driver ST:              token-dest-dn()
    [11/19/21 19:14:22.838]:Active Directory Driver PT:
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="Active Directory Driver##17d3a42b230##0" level="warning">Code(-8019) Operation vetoed on unassociated object.<application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local(data\users\actives\ecampos)</object-dn>
          <component>Publisher</component>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:22.838]:Active Directory Driver ST:                Token Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:22.869]:Active Directory Driver PT:Remote Interface Driver: Document sent.
    [11/19/21 19:14:22.869]:Active Directory Driver ST:              Arg Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:22.869]:Active Directory Driver PT:Remote Interface Driver: Waiting for receive...
    [11/19/21 19:14:22.869]:Active Directory Driver ST:          Action: do-set-xml-attr("association-ref","../modify[last()]/modify-attr[last()]/add-value[last()]/value[last()]",token-xpath("./text()")).
    [11/19/21 19:14:22.885]:Active Directory Driver ST:            arg-string(token-xpath("./text()"))
    [11/19/21 19:14:22.885]:Active Directory Driver ST:              token-xpath("./text()")
    [11/19/21 19:14:22.885]:Active Directory Driver ST:                Token Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:22.885]:Active Directory Driver ST:              Arg Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:22.885]:Active Directory Driver ST:        Performing actions for local-variable(current-node) = <entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1".
    [11/19/21 19:14:22.885]:Active Directory Driver ST:          Action: do-set-local-variable("group-assoc",scope="policy",token-xpath("es:getEntParamField($current-node,'ID')
    ")).
    [11/19/21 19:14:22.900]:Active Directory Driver ST:            arg-string(token-xpath("es:getEntParamField($current-node,'ID')
    "))
    [11/19/21 19:14:22.900]:Active Directory Driver ST:              token-xpath("es:getEntParamField($current-node,'ID')
    ")
    [11/19/21 19:14:22.900]:Active Directory Driver ST:                Token Value: "671c6dd7b9cf5e4484fc7f3d6d1112d6".
    [11/19/21 19:14:22.916]:Active Directory Driver ST:              Arg Value: "671c6dd7b9cf5e4484fc7f3d6d1112d6".
    [11/19/21 19:14:22.917]:Active Directory Driver ST:          Action: do-add-src-attr-value("member",class-name="group",arg-association(token-local-variable("group-assoc")),token-dest-dn()).
    [11/19/21 19:14:22.917]:Active Directory Driver ST:            arg-association(token-local-variable("group-assoc"))
    [11/19/21 19:14:22.917]:Active Directory Driver ST:              token-local-variable("group-assoc")
    [11/19/21 19:14:22.933]:Active Directory Driver ST:                Token Value: "671c6dd7b9cf5e4484fc7f3d6d1112d6".
    [11/19/21 19:14:22.933]:Active Directory Driver ST:              Arg Value: "671c6dd7b9cf5e4484fc7f3d6d1112d6".
    [11/19/21 19:14:22.933]:Active Directory Driver ST:            arg-string(token-dest-dn())
    [11/19/21 19:14:22.933]:Active Directory Driver ST:              token-dest-dn()
    [11/19/21 19:14:22.933]:Active Directory Driver ST:                Token Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:22.948]:Active Directory Driver ST:              Arg Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:22.948]:Active Directory Driver ST:          Action: do-set-xml-attr("association-ref","../modify[last()]/modify-attr[last()]/add-value[last()]/value[last()]",token-xpath("./text()")).
    [11/19/21 19:14:22.948]:Active Directory Driver ST:            arg-string(token-xpath("./text()"))
    [11/19/21 19:14:22.964]:Active Directory Driver ST:              token-xpath("./text()")
    [11/19/21 19:14:22.964]:Active Directory Driver ST:                Token Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:22.964]:Active Directory Driver ST:              Arg Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:22.964]:Active Directory Driver ST:        Performing actions for local-variable(current-node) = <entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1".
    [11/19/21 19:14:22.980]:Active Directory Driver ST:          Action: do-set-local-variable("group-assoc",scope="policy",token-xpath("es:getEntParamField($current-node,'ID')
    ")).
    [11/19/21 19:14:22.980]:Active Directory Driver ST:            arg-string(token-xpath("es:getEntParamField($current-node,'ID')
    "))
    [11/19/21 19:14:22.995]:Active Directory Driver ST:              token-xpath("es:getEntParamField($current-node,'ID')
    ")
    [11/19/21 19:14:22.995]:Active Directory Driver ST:                Token Value: "bf1f74ec26ca32488e7bb34f5853bc32".
    [11/19/21 19:14:22.995]:Active Directory Driver ST:              Arg Value: "bf1f74ec26ca32488e7bb34f5853bc32".
    [11/19/21 19:14:22.995]:Active Directory Driver ST:          Action: do-add-src-attr-value("member",class-name="group",arg-association(token-local-variable("group-assoc")),token-dest-dn()).
    [11/19/21 19:14:23.011]:Active Directory Driver ST:            arg-association(token-local-variable("group-assoc"))
    [11/19/21 19:14:23.011]:Active Directory Driver ST:              token-local-variable("group-assoc")
    [11/19/21 19:14:23.011]:Active Directory Driver ST:                Token Value: "bf1f74ec26ca32488e7bb34f5853bc32".
    [11/19/21 19:14:23.011]:Active Directory Driver ST:              Arg Value: "bf1f74ec26ca32488e7bb34f5853bc32".
    [11/19/21 19:14:23.011]:Active Directory Driver ST:            arg-string(token-dest-dn())
    [11/19/21 19:14:23.026]:Active Directory Driver ST:              token-dest-dn()
    [11/19/21 19:14:23.026]:Active Directory Driver ST:                Token Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:23.026]:Active Directory Driver ST:              Arg Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:23.026]:Active Directory Driver ST:          Action: do-set-xml-attr("association-ref","../modify[last()]/modify-attr[last()]/add-value[last()]/value[last()]",token-xpath("./text()")).
    [11/19/21 19:14:23.042]:Active Directory Driver ST:            arg-string(token-xpath("./text()"))
    [11/19/21 19:14:23.042]:Active Directory Driver ST:              token-xpath("./text()")
    [11/19/21 19:14:23.042]:Active Directory Driver ST:                Token Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:23.042]:Active Directory Driver ST:              Arg Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:23.058]:Active Directory Driver ST:        Performing actions for local-variable(current-node) = <entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1".
    [11/19/21 19:14:23.058]:Active Directory Driver ST:          Action: do-set-local-variable("group-assoc",scope="policy",token-xpath("es:getEntParamField($current-node,'ID')
    ")).
    [11/19/21 19:14:23.073]:Active Directory Driver ST:            arg-string(token-xpath("es:getEntParamField($current-node,'ID')
    "))
    [11/19/21 19:14:23.073]:Active Directory Driver ST:              token-xpath("es:getEntParamField($current-node,'ID')
    ")
    [11/19/21 19:14:23.073]:Active Directory Driver ST:                Token Value: "95d0b40948ed9a4ea778ef41637a0a16".
    [11/19/21 19:14:23.073]:Active Directory Driver ST:              Arg Value: "95d0b40948ed9a4ea778ef41637a0a16".
    [11/19/21 19:14:23.089]:Active Directory Driver ST:          Action: do-add-src-attr-value("member",class-name="group",arg-association(token-local-variable("group-assoc")),token-dest-dn()).
    [11/19/21 19:14:23.089]:Active Directory Driver ST:            arg-association(token-local-variable("group-assoc"))
    [11/19/21 19:14:23.089]:Active Directory Driver ST:              token-local-variable("group-assoc")
    [11/19/21 19:14:23.089]:Active Directory Driver ST:                Token Value: "95d0b40948ed9a4ea778ef41637a0a16".
    [11/19/21 19:14:23.105]:Active Directory Driver ST:              Arg Value: "95d0b40948ed9a4ea778ef41637a0a16".
    [11/19/21 19:14:23.105]:Active Directory Driver ST:            arg-string(token-dest-dn())
    [11/19/21 19:14:23.105]:Active Directory Driver ST:              token-dest-dn()
    [11/19/21 19:14:23.105]:Active Directory Driver ST:                Token Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:23.105]:Active Directory Driver ST:              Arg Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:23.105]:Active Directory Driver ST:          Action: do-set-xml-attr("association-ref","../modify[last()]/modify-attr[last()]/add-value[last()]/value[last()]",token-xpath("./text()")).
    [11/19/21 19:14:23.120]:Active Directory Driver ST:            arg-string(token-xpath("./text()"))
    [11/19/21 19:14:23.120]:Active Directory Driver ST:              token-xpath("./text()")
    [11/19/21 19:14:23.120]:Active Directory Driver ST:                Token Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:23.120]:Active Directory Driver ST:              Arg Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:23.136]:Active Directory Driver ST:        Performing actions for local-variable(current-node) = <entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1".
    [11/19/21 19:14:23.136]:Active Directory Driver ST:          Action: do-set-local-variable("group-assoc",scope="policy",token-xpath("es:getEntParamField($current-node,'ID')
    ")).
    [11/19/21 19:14:23.136]:Active Directory Driver ST:            arg-string(token-xpath("es:getEntParamField($current-node,'ID')
    "))
    [11/19/21 19:14:23.151]:Active Directory Driver ST:              token-xpath("es:getEntParamField($current-node,'ID')
    ")
    [11/19/21 19:14:23.151]:Active Directory Driver ST:                Token Value: "4e542b9188116e44baab8495d8f33f45".
    [11/19/21 19:14:23.151]:Active Directory Driver ST:              Arg Value: "4e542b9188116e44baab8495d8f33f45".
    [11/19/21 19:14:23.167]:Active Directory Driver ST:          Action: do-add-src-attr-value("member",class-name="group",arg-association(token-local-variable("group-assoc")),token-dest-dn()).
    [11/19/21 19:14:23.167]:Active Directory Driver ST:            arg-association(token-local-variable("group-assoc"))
    [11/19/21 19:14:23.167]:Active Directory Driver ST:              token-local-variable("group-assoc")
    [11/19/21 19:14:23.167]:Active Directory Driver ST:                Token Value: "4e542b9188116e44baab8495d8f33f45".
    [11/19/21 19:14:23.183]:Active Directory Driver ST:              Arg Value: "4e542b9188116e44baab8495d8f33f45".
    [11/19/21 19:14:23.183]:Active Directory Driver ST:            arg-string(token-dest-dn())
    [11/19/21 19:14:23.183]:Active Directory Driver ST:              token-dest-dn()
    [11/19/21 19:14:23.183]:Active Directory Driver ST:                Token Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:23.183]:Active Directory Driver ST:              Arg Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:23.183]:Active Directory Driver ST:          Action: do-set-xml-attr("association-ref","../modify[last()]/modify-attr[last()]/add-value[last()]/value[last()]",token-xpath("./text()")).
    [11/19/21 19:14:23.183]:Active Directory Driver ST:            arg-string(token-xpath("./text()"))
    [11/19/21 19:14:23.198]:Active Directory Driver ST:              token-xpath("./text()")
    [11/19/21 19:14:23.198]:Active Directory Driver ST:                Token Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:23.198]:Active Directory Driver ST:              Arg Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:23.198]:Active Directory Driver ST:        Performing actions for local-variable(current-node) = <entitlement-impl> @id = "" @name = "Group" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1".
    [11/19/21 19:14:23.198]:Active Directory Driver ST:          Action: do-set-local-variable("group-assoc",scope="policy",token-xpath("es:getEntParamField($current-node,'ID')
    ")).
    [11/19/21 19:14:23.198]:Active Directory Driver ST:            arg-string(token-xpath("es:getEntParamField($current-node,'ID')
    "))
    [11/19/21 19:14:23.214]:Active Directory Driver ST:              token-xpath("es:getEntParamField($current-node,'ID')
    ")
    [11/19/21 19:14:23.214]:Active Directory Driver ST:                Token Value: "bc51f415c2a03e41b4a8b86df398fe97".
    [11/19/21 19:14:23.214]:Active Directory Driver ST:              Arg Value: "bc51f415c2a03e41b4a8b86df398fe97".
    [11/19/21 19:14:23.214]:Active Directory Driver ST:          Action: do-add-src-attr-value("member",class-name="group",arg-association(token-local-variable("group-assoc")),token-dest-dn()).
    [11/19/21 19:14:23.230]:Active Directory Driver ST:            arg-association(token-local-variable("group-assoc"))
    [11/19/21 19:14:23.230]:Active Directory Driver ST:              token-local-variable("group-assoc")
    [11/19/21 19:14:23.230]:Active Directory Driver ST:                Token Value: "bc51f415c2a03e41b4a8b86df398fe97".
    [11/19/21 19:14:23.230]:Active Directory Driver ST:              Arg Value: "bc51f415c2a03e41b4a8b86df398fe97".
    [11/19/21 19:14:23.230]:Active Directory Driver ST:            arg-string(token-dest-dn())
    [11/19/21 19:14:23.245]:Active Directory Driver ST:              token-dest-dn()
    [11/19/21 19:14:23.245]:Active Directory Driver ST:                Token Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:23.245]:Active Directory Driver ST:              Arg Value: "\SMU\data\users\actives\bgongora".
    [11/19/21 19:14:23.245]:Active Directory Driver ST:          Action: do-set-xml-attr("association-ref","../modify[last()]/modify-attr[last()]/add-value[last()]/value[last()]",token-xpath("./text()")).
    [11/19/21 19:14:23.245]:Active Directory Driver ST:            arg-string(token-xpath("./text()"))
    [11/19/21 19:14:23.261]:Active Directory Driver ST:              token-xpath("./text()")
    [11/19/21 19:14:23.261]:Active Directory Driver ST:                Token Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:23.261]:Active Directory Driver ST:              Arg Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:23.261]:Active Directory Driver ST:    Evaluating selection criteria for rule 'Check target of add-association for Exchange mailbox entitlements'.
    [11/19/21 19:14:23.276]:Active Directory Driver ST:      (if-global-variable 'drv.exchMailboxMethod' equal "entitlement") = TRUE.
    [11/19/21 19:14:23.276]:Active Directory Driver ST:      (if-operation equal "add-association") = TRUE.
    [11/19/21 19:14:23.276]:Active Directory Driver ST:      (if-op-property 'check-exch-mailbox-entitlements' equal "true") = TRUE.
    [11/19/21 19:14:23.276]:Active Directory Driver ST:      (if-entitlement 'ExchangeMailbox' available) = TRUE.
    [11/19/21 19:14:23.292]:Active Directory Driver ST:    Rule selected.
    [11/19/21 19:14:23.292]:Active Directory Driver ST:    Applying rule 'Check target of add-association for Exchange mailbox entitlements'.
    [11/19/21 19:14:23.292]:Active Directory Driver ST:      Action: do-for-each(arg-node-set(token-entitlement("ExchangeMailbox"))).
    [11/19/21 19:14:23.292]:Active Directory Driver ST:        arg-node-set(token-entitlement("ExchangeMailbox"))
    [11/19/21 19:14:23.292]:Active Directory Driver ST:          token-entitlement("ExchangeMailbox")
    [11/19/21 19:14:23.308]:Active Directory Driver ST:          Token Value: {<entitlement-impl> @id = "" @name = "ExchangeMailbox" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1"}.
    [11/19/21 19:14:23.308]:Active Directory Driver ST:          Arg Value: {<entitlement-impl> @id = "" @name = "ExchangeMailbox" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1"}.
    [11/19/21 19:14:23.308]:Active Directory Driver ST:        Performing actions for local-variable(current-node) = <entitlement-impl> @id = "" @name = "ExchangeMailbox" @qualified-src-dn = "O=data\OU=users\OU=actives\CN=bgongora" @src = "UA" @src-dn = "\SMU\data\users\actives\bgongora" @src-entry-id = "256190" @state = "1".
    [11/19/21 19:14:23.323]:Active Directory Driver ST:          Action: do-set-local-variable("homeMDB",scope="policy",token-xpath("es:getEntParamField($current-node,'ID')")).
    [11/19/21 19:14:23.323]:Active Directory Driver ST:            arg-string(token-xpath("es:getEntParamField($current-node,'ID')"))
    [11/19/21 19:14:23.323]:Active Directory Driver ST:              token-xpath("es:getEntParamField($current-node,'ID')")
    [11/19/21 19:14:23.339]:Active Directory Driver ST:                Token Value: "CN=New Base 60MG,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Rendic,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=rendic,DC=local".
    [11/19/21 19:14:23.339]:Active Directory Driver ST:              Arg Value: "CN=New Base 60MG,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Rendic,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=rendic,DC=local".
    [11/19/21 19:14:23.355]:Active Directory Driver ST:          Action: do-set-src-attr-value("homeMDB",arg-association(token-xpath("./text()")),token-local-variable("homeMDB")).
    [11/19/21 19:14:23.355]:Active Directory Driver ST:            arg-association(token-xpath("./text()"))
    [11/19/21 19:14:23.355]:Active Directory Driver ST:              token-xpath("./text()")
    [11/19/21 19:14:23.355]:Active Directory Driver ST:                Token Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:23.370]:Active Directory Driver ST:              Arg Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:23.370]:Active Directory Driver ST:            arg-string(token-local-variable("homeMDB"))
    [11/19/21 19:14:23.370]:Active Directory Driver ST:              token-local-variable("homeMDB")
    [11/19/21 19:14:23.370]:Active Directory Driver ST:                Token Value: "CN=New Base 60MG,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Rendic,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=rendic,DC=local".
    [11/19/21 19:14:23.386]:Active Directory Driver ST:              Arg Value: "CN=New Base 60MG,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Rendic,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=rendic,DC=local".
    [11/19/21 19:14:23.386]:Active Directory Driver ST:          Action: do-set-src-attr-value("mailNickname",arg-association(token-xpath("./text()")),token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name()))).
    [11/19/21 19:14:23.401]:Active Directory Driver ST:            arg-association(token-xpath("./text()"))
    [11/19/21 19:14:23.401]:Active Directory Driver ST:              token-xpath("./text()")
    [11/19/21 19:14:23.401]:Active Directory Driver ST:                Token Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:23.401]:Active Directory Driver ST:              Arg Value: "1600fb61f1f4af4d93d4da4ba4cb15a2".
    [11/19/21 19:14:23.401]:Active Directory Driver ST:            arg-string(token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name())))
    [11/19/21 19:14:23.417]:Active Directory Driver ST:              token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name()))
    [11/19/21 19:14:23.417]:Active Directory Driver ST:                token-substring(length="20",token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name()))
    [11/19/21 19:14:23.433]:Active Directory Driver ST:                  token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name())
    [11/19/21 19:14:23.433]:Active Directory Driver ST:                    token-replace-all("[^a-zA-Z0-9\x21\x23-\x29\x2d\x2e\x40\x5e-\x60\x7b\x7d\x7e\xc0-\xf6\xf8-\xff\u0410-\u044f]","",token-src-name())
    [11/19/21 19:14:23.433]:Active Directory Driver ST:                      token-src-name()
    [11/19/21 19:14:23.433]:Active Directory Driver ST:                        Token Value: "".
    [11/19/21 19:14:23.433]:Active Directory Driver ST:                      Arg Value: "".
    [11/19/21 19:14:23.433]:Active Directory Driver ST:                    Token Value: "".
    [11/19/21 19:14:23.433]:Active Directory Driver ST:                  Arg Value: "".
    [11/19/21 19:14:23.433]:Active Directory Driver ST:                Token Value: "".
    [11/19/21 19:14:23.433]:Active Directory Driver ST:              Arg Value: "".
    [11/19/21 19:14:23.433]:Active Directory Driver ST:  Direct command from policy
    [11/19/21 19:14:23.433]:Active Directory Driver ST:  
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="group" event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128">
          <association>19d7d87749815c4bb6182a3293db8d63</association>
          <modify-attr attr-name="member">
            <add-value>
              <value association-ref="1600fb61f1f4af4d93d4da4ba4cb15a2" type="dn">\SMU\data\users\actives\bgongora</value>
            </add-value>
          </modify-attr>
          <operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\bgongora" AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" AccountTracking-sAMAccountName="bgongora" AccountTracking-userPrincipalName="bgongora@unimarc.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=bgongora,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
            <entitlement-impl id="" name="Group" qualified-src-dn="O=data\OU=users\OU=actives\CN=bgongora" src="UA" src-dn="\SMU\data\users\actives\bgongora" src-entry-id="256190" state="1">{"ID":"19d7d87749815c4bb6182a3293db8d63","ID2":"CN=All SO,OU=Grupos,DC=unimarc,DC=local"}</entitlement-impl>
          </operation-data>
        </modify>
      </input>
    </nds>
    [11/19/21 19:14:23.448]:Active Directory Driver ST:  Submitting document to subscriber shim:
    [11/19/21 19:14:23.448]:Active Directory Driver ST:  
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify class-name="group" event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128">
          <association>19d7d87749815c4bb6182a3293db8d63</association>
          <modify-attr attr-name="member">
            <add-value>
              <value association-ref="1600fb61f1f4af4d93d4da4ba4cb15a2" type="dn">\SMU\data\users\actives\bgongora</value>
            </add-value>
          </modify-attr>
          <operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\bgongora" AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" AccountTracking-sAMAccountName="bgongora" AccountTracking-userPrincipalName="bgongora@unimarc.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=bgongora,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
            <entitlement-impl id="" name="Group" qualified-src-dn="O=data\OU=users\OU=actives\CN=bgongora" src="UA" src-dn="\SMU\data\users\actives\bgongora" src-entry-id="256190" state="1">{"ID":"19d7d87749815c4bb6182a3293db8d63","ID2":"CN=All SO,OU=Grupos,DC=unimarc,DC=local"}</entitlement-impl>
          </operation-data>
        </modify>
      </input>
    </nds>

    After a lot of events (related to groups) I found homeMDB setting.
    This event returns missing classname error:


    [11/19/21 19:14:40.119]:Active Directory Driver ST:  Submitting document to subscriber shim:
    [11/19/21 19:14:40.119]:Active Directory Driver ST:  
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128">
          <association>1600fb61f1f4af4d93d4da4ba4cb15a2</association>
          <modify-attr attr-name="homeMDB">
            <remove-all-values/>
            <add-value>
              <value type="string">CN=New Base 60MG,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Rendic,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=rendic,DC=local</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="mailNickname">
            <remove-all-values/>
            <add-value>
              <value type="string"/>
            </add-value>
          </modify-attr>
          <operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\bgongora" AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" AccountTracking-sAMAccountName="bgongora" AccountTracking-userPrincipalName="bgongora@unimarc.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=bgongora,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
            <entitlement-impl id="" name="ExchangeMailbox" qualified-src-dn="O=data\OU=users\OU=actives\CN=bgongora" src="UA" src-dn="\SMU\data\users\actives\bgongora" src-entry-id="256190" state="1">{"ID":"CN=New Base 60MG,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Rendic,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=rendic,DC=local"}</entitlement-impl>
          </operation-data>
        </modify>
      </input>
    </nds>
    [11/19/21 19:14:40.135]:Active Directory Driver ST:  Stripping operation data from input document
    [11/19/21 19:14:40.135]:Active Directory Driver ST:  Remote Interface Driver: Sending...
    [11/19/21 19:14:40.135]:Active Directory Driver ST:  
    <nds dtdversion="4.0" ndsversion="8.x">
      <source>
        <product edition="Advanced" version="4.8.3.1">DirXML</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <input>
        <modify event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128">
          <association>1600fb61f1f4af4d93d4da4ba4cb15a2</association>
          <modify-attr attr-name="homeMDB">
            <remove-all-values/>
            <add-value>
              <value type="string">CN=New Base 60MG,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Rendic,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=rendic,DC=local</value>
            </add-value>
          </modify-attr>
          <modify-attr attr-name="mailNickname">
            <remove-all-values/>
            <add-value>
              <value type="string"/>
            </add-value>
          </modify-attr>
        </modify>
      </input>
    </nds>
    [11/19/21 19:14:40.150]:Active Directory Driver ST:  Remote Interface Driver: Document sent.
    [11/19/21 19:14:40.150]:Active Directory Driver ST:  Remote Interface Driver: Received
    [11/19/21 19:14:40.150]:Active Directory Driver ST:  
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20191128_120000" instance="\SMU\system\driverset1\Active Directory Driver" version="4.1.3.0">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128" level="error" text1="Missing ClassName" type="driver-general"/>
      </output>
    </nds>
    [11/19/21 19:14:40.150]:Active Directory Driver ST:  Remote Interface Driver: Received command: SUBSCRIBER REPLY(10).
    [11/19/21 19:14:40.150]:Active Directory Driver ST:  Restoring operation data to output document
    [11/19/21 19:14:40.150]:Active Directory Driver ST:  SubscriptionShim.execute() returned:
    [11/19/21 19:14:40.150]:Active Directory Driver ST:  
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20191128_120000" instance="\SMU\system\driverset1\Active Directory Driver" version="4.1.3.0">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128" level="error" text1="Missing ClassName" type="driver-general">
          <operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\bgongora" AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" AccountTracking-sAMAccountName="bgongora" AccountTracking-userPrincipalName="bgongora@unimarc.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=bgongora,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
            <entitlement-impl id="" name="ExchangeMailbox" qualified-src-dn="O=data\OU=users\OU=actives\CN=bgongora" src="UA" src-dn="\SMU\data\users\actives\bgongora" src-entry-id="256190" state="1">{"ID":"CN=New Base 60MG,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Rendic,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=rendic,DC=local"}</entitlement-impl>
          </operation-data>
        </status>
      </output>
    </nds>
    [11/19/21 19:14:40.166]:Active Directory Driver ST:  Processing returned document.
    [11/19/21 19:14:40.166]:Active Directory Driver ST:  Processing operation <status> for .
    [11/19/21 19:14:40.166]:Active Directory Driver ST:  
    DirXML Log Event -------------------
         Driver:   \SMU\system\driverset1\Active Directory Driver
         Channel:  Subscriber
         Object:   \SMU\data\users\actives\bgongora
         Status:   Error
    [11/19/21 19:14:40.713]:Active Directory Driver ST:  Direct command from policy result
    [11/19/21 19:14:40.713]:Active Directory Driver ST:  
    <nds dtdversion="1.1" ndsversion="8.7">
      <source>
        <product asn1id="" build="20191128_120000" instance="\SMU\system\driverset1\Active Directory Driver" version="4.1.3.0">AD</product>
        <contact>NetIQ Corporation</contact>
      </source>
      <output>
        <status event-id="HOSGMSSGIEDIR-NDS#20211119221310#1#6:16e08778-08ff-4ad5-92ea-580a4f3ea128" level="error" text1="Missing ClassName" type="driver-general">
          <operation-data AccountTracking-AccountStatusChanged="true" AccountTracking-AppAccountStatus="-" AccountTracking-IdvAccountStatus="A" AccountTracking-LDAPDN="CN=Blanca Gongora Mesias,OU=Usuarios Unimarc,DC=unimarc,DC=local" AccountTracking-ObjectDN="\SMU\data\users\actives\bgongora" AccountTracking-Operation="add" AccountTracking-association="1600fb61f1f4af4d93d4da4ba4cb15a2" AccountTracking-sAMAccountName="bgongora" AccountTracking-userPrincipalName="bgongora@unimarc.local" attempt-to-match="true" check-exch-mailbox-entitlements="true" check-group-entitlements="true" unmatched-src-dn="CN=bgongora,OU=actives">
            <password-subscribe-status>
              <association/>
            </password-subscribe-status>
            <entitlement-impl id="" name="ExchangeMailbox" qualified-src-dn="O=data\OU=users\OU=actives\CN=bgongora" src="UA" src-dn="\SMU\data\users\actives\bgongora" src-entry-id="256190" state="1">{"ID":"CN=New Base 60MG,CN=Databases,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=Rendic,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=rendic,DC=local"}</entitlement-impl>
          </operation-data>
          <application>DirXML</application>
          <module>Active Directory Driver</module>
          <object-dn>\SMU\data\users\actives\bgongora</object-dn>
          <component>Subscriber</component>
        </status>
      </output>
    </nds>

    This error also appears in dev lab and even so in that laboratory the mail is created. I will include user class