I also use an ldap attribute map. In my case, the ldap attribute map matches to a group policy, and that group policy maps to an assigned address pool. So, if you were a defined user in an undefuned group, you would not receive an IP address from t...