ZPA is a Centrify utility that can be used for automatic provisioning. It can UNIX-enable Active Directory users and groups. Read this post to learn about ZPA:
Configuration and Testing
Errata- Identity overrides can happen at the zone level, child zone level and system level.
- It's recommended that you install in the Centrify common components (for troubleshooting purposes)
- The UNIX Super Users group also needs to be nested in the provisioning group, otherwise they will lose their UNIX profile.
- The ZPA account needs to be made a local administrator in APP1 (if you want the troubleshooting components to work)
- The Provisioning tab under zone properties needs to be installed on CLIENT1 using ZPA setup.