It looks as though both AD and LDAP module cannot remove a value from a multi-valued attribute properly. AD doesn’t even have an option to remove a an attribute, and ldap errors when attempting to because it seems snaplogic sees an empty member list ...