It looks as though both AD and LDAP module cannot remove a value from a multi-valued attribute properly. AD doesn’t even have an option to remove a an attribute, and ldap errors when attempting to because it seems snaplogic sees an empty member list when checking for membership first. The reason it is empty looks to be in the way snaplogic obtains member attribute values, and does not populate the member attribute but populates it in the range attribute.
Thank you for posting on our Community boards! Could you share more details about the errors and pipeline design so we can help? If it isn’t something you want to share publicly, please contact out Support team so we can help you directly.