I got some attributes to user from couple source to identity vault.
....
After these attributes are available create rule of Edirectory driver passes
User to Production Tree..
Group is create with attribute info and user is added to group in
Production tree driver... Works Well..

<rule>
<description>Create Groups base on EnteringGroup attribute</description>
<conditions>
<and>
<if-operation op="equal">add</if-operation>
<if-class-name mode="nocase" op="equal">User</if-class-name>
<if-op-attr name="EnteringGroup" op="available"/>
</and>
</conditions>
<actions>
<do-add-dest-object class-name="Group" direct="true">
<arg-dn>
<token-text xml:space="preserve">Org\Groups\</token-text>
<token-text xml:space="preserve">EnteringGroup</token-text>
<token-text xml:space="preserve">\</token-text>
<token-op-attr name="EnteringGroup"/>
</arg-dn>
</do-add-dest-object>
</actions>
</rule>

<rule>
<description>Add User to Group based on EnteringGroup
attribute</description>
<conditions>
<and>
<if-class-name mode="nocase" op="equal">User</if-class-name>
<if-op-attr name="EnteringGroup" op="available"/>
</and>
</conditions>
<actions>
<do-set-dest-attr-value name="Group Membership">
<arg-value type="string">
<token-text xml:space="preserve">Org\Groups\</token-text>
<token-text xml:space="preserve">EnteringGroup</token-text>
<token-text xml:space="preserve">\</token-text>
<token-op-attr name="EnteringGroup"/>
</arg-value>
</do-set-dest-attr-value>
</actions>
</rule>


However - I would like to have group and membership syncronized back to
identity vault automatically after creation... Now I can get info bck only
with migrate button...

How could I do that ? I have tried to tune Filter -merge authority - but no
success..

BR. Veli-Matti