Refactor GroupMemberPolicy such that Group access tokens can support LDAP sync
Based on a reported bug it was identified that a refactor to the create_service had exposed a gap where Group access tokens could no longer be created for groups setup for LDAP sync.
In order to restore that functionality the refactor was reverted however we need to revisit the handling of group access tokens within a LDAP group sync setup to reflect the proposal here