<div dir="ltr"><div dir="ltr">hi,<div><br></div><div>Is there some access control rule on the AD that only releases that attribute value from LDAP to the IP address of your original IdP and hence your clone doesn't receive it? </div><div><br></div><div>ala</div></div><div dir="ltr" class="gmail_signature"><br></div></div>