I touched on this subject in previous posts, but now understand what the customer would like to see.
Ideally, when an admin creates a new user within FIM, the user is provisioned into AD DOMAIN_A. DOMAIN_A is considered the authoritative source for the env.
If a power user is oboarded, the user will be provisioned into AD DOMAIN_A and AD DOMAIN_B and a SQL store.
Is this primarily what Sets are for, to manage which type of user gets what set of rules applied, hence where they are provisioned? Any other suggestions on how to approach this.
Thanks!