If you enable role assignment synchronization, then you manage role assignments for users in the LDAP directory service. Role assignments are synchronized to the user account in Data Archive when users log in to Data Archive. Role assignments are only synchronized for users that exist in Data Archive.
When users log in, Data Archive connects to the LDAP directory service and reviews all of the role assignments for the user. Data Archive synchronizes the user account to match role assignments in the LDAP directory service. If there are any changes, such as if you add or delete a role assignment in the LDAP directory service, Data Archive updates the roles for the corresponding user account.
Data Archive only synchronizes role assignments from the LDAP directory service. The synchronization does not include roles or security groups.
If you change role assignments while a user is logged in to Data Archive, the changes are synchronized the next time the user logs in to Data Archive.