I am curious at what point your doing this? I have a set of challenge questions and answers in an LDAP that I would like to use to populate the fields inside of iDM. This way, I could utilze the iDM screens/logic when a user forgets their password. I would also need to keep these fields updated in iDM as they could change in the LDAP. Any suggestions?