Thanks Tobias
my overall concern is
" User is already present in Target System"(AD) and i want to assign groups to them.
" When i assign a account privilege to user, it should not create user in AD instead it should just check and put the status to OK state(without actually provisioning).
" As group membership will look for Account ADS attribute before it assign the group to user in target system and this will be only possible if the account status is in ok state.
So it will act as dummy provisioning and will perform the group membership based on the provisioning status