2779d42e6c
syncBoundGroupsForTenant() compared cn/dn for byte equality, so any casing difference AD returns between two runs (e.g. after a domain-controller switch) would look like a rename and re-write name/ldapDn every single sync — violating the 'sync twice over an unchanged AD state = no-op' idempotency guarantee. The comparison used to DECIDE 'is this a rename' is now case-insensitive; the value written on an actual rename is still stored byte-for-byte as the directory reports it, per D-03.