we successfully created a workflow for provisioning users and assigning AD-groups based on another user.
what we are experiencing is that always the same groups can't be assigned. Narrowing it down we found out that only groups in folders "users" and "groups" in the root of our domain are failing. all other groups are handled correctly.
checking the permissions of both folders showed that the user we are using for this operation are allowed to do that. And additionally it is possible to add users to those groups with this user.
Has anyone any idea what is going on here?