@anupampat , I run into same issue sometimes. Solution is to DELETE the user at AEM, and allow to federate once again. When a federated user is created from ims, the groups assigned at adminconsole is added and its permission are appliedwhen groups are modified at adminconsole, they dont automatical...