Not synchornized data using AD/Internal Hybrid

Hi!

I have an AD/Internal Hybrid user source.

The user source gets populated with the usernames, names, emails and phones from the AD.
Roles are configured in the gateway.

There is something that I don't understand. I can edit the contact info and it stays like that, doesn't get refreshed by the AD. So now the AD has one email and the Gateway has another one. I suppose this is intended because I'm using AD/Internal Hybrid but we really don't like that.

How should I aproach this? I want to be able to edit it on the Gateway and the change gets synchronized to the AD or I would like to disable it completly.

Something in this doesn't seem right. Any help is appreciated.

Thx!

Ignition cannot change information in AD. Full stop.

The solution is to not use hybrid. Rely on AD for everything, including roles, and use external tools and/or web APIs to pass changes to AD.