Given SES around the corner, it's ideal to enable SSO with IMS especially for big companies
traditionally, big companies rely upon AD to sync AD users & user groups in, then control PW access based upon PW groups (sync'd from AD)
To facilitate them to migrate from AD to IMS, suggest we enhance User Sync service to
a. scan target AD groups, create new IMS accounts or disable IMS accounts which disabled in AD
b. create PW groups from target AD groups