I setup a sync between edir and AD a couple weeks ago. Now numerous
edir accounts are having their loginExpirationTime attribute set to
December 31, 1969.

I used ICE to export those users, modified the LDIF file to remove the
logonExpirationTime values for users, and imported the changes. But IDM
seems to have reversed my changes and set the accounts to expire again.
I had to disable the directory synchronization to terminate this loop.

I checked the comparable attribute in AD for a user whose edir
loginExpirationTime attribute was set to Dec 31, 1969 and it was NOT set
to expire in AD...

Using IDM 3.6.1.

What gives?

