There are issues with how AD Integration syncs TPAM users with AD integrated groups. There are automated processes in place that will remove an Active Directory (AD) user account from all of their AD integrated groups, but will leave the UserID enabled in TPAM. However, when that same AD user account is added back to AD integrated groups in AD, TPAM will not sync that user account because the UserID already exists in TPAM as an enabled user. Is there a workaround for this?
解决办法
In this scenario, it is recommended to use the default settings for the "Collision Strategy":