Hello there.

I chose to try to completely replace a real old AD driver with a new one,
in a system I have sort of inherited.

That went almost ok. Fortunately were still in the development system

The old drivers group entitlements were the old type, where you have a
single entitlement value, the association value to the AD driver from the

Now, the new Group entitlement have this fine JSON thing with ID:
[Association] ID2:[SourceDistringuishedName].

Pretty nice, and beatifully readable.

The issue here, is that all the systems resource objects (and there is a
lot) now have invalid entitlement values, and the entitlement consumers
(the user objects) also have invalid values.

Does anyone have a good idea to what I can do about it?