You can add users that already exist as native directory principal objects to be members of a mechanism. For example:
dn: cn=ldap,ou=mechanisms,ou=policy1,ou=tdatrootP,dc=domain1,dc=com changetype: modify add: member member: cn=jcm,ou=users,ou=system1,ou=tdatrootA,dc=domain1,dc=com
When addition of a directory principal member is required, use the form:
member: uid=dirUser1,ou=principals,dc=domain1,dc=com