Allow PAM to join MIM Sets
The basic of PAM is that you have to activate privileges... But somehow MIM cannot do this for itself?
(Correct me if I am wrong, but I was unable to create a Set that targets users who have activated a PAM role.. I was able to target the PAM Requests, but not extract the users)
Alternatively: Allow Security Groups in AD to be a member of a set directly, not with Sync.