Hi Deyster,
I guess we missed this post. It's too late but let me attempt to answer this:
Can you see the desired attributes under Users and Identity Stores > External Identity Stores > Active Directory, then click the Directory Attributes tab.
Enter the name of a domain user. Click to access the Attributes secondary window, which displays the attributes of the name you entered in the previous field.
If you see the desired attribute, you can select that attribute from the list, then click Edit to edit the attribute.
Click Add to add an attribute to the Attribute Name list.
After that go to the access-policies > authorization policy > click on customize (right bottom corner)> select/move the desired attribute to the righ end side > Ok.
Now click on create > enter the value of that attribute.
Please give a try with the above suggested steps and let me know.
~BR
Jatin Katyal
**Do rate helpful posts**
~Jatin