Anybody know how to do an extensionable match filter to return nrf based ID values, or DirXML-Entitlement values?

Identity Governance reports warnings of duplicates found when doing a collection. It indicates a permisionId value with something like:

{"permisionId"."{\"ID\".\"3069B28A954543453\", \"ID2"\.\"cn=costcenter-A23423423,ou=groups........

I am wanting to search eDirectory against the nrf attributes or entitlement attributes for the ID value listed above in hopes of finding the duplicate assignments. However, with it being a structured attribute and with the nrf attributes holding data prior to the ID and after the ID, I can't do a *<ID value>* in the filter.

I'm assuming there is an OID LDAP control search..