- In LDAP, group membership is generally controled via multi-valued member attributes of group entries instead of group-user hierarchies.
- When a new user entry has been created, assign him to a default group which all users are member of.
- When a user entry has been deleted, remove him from all groups he was member of.
