We are interested in this as well.
For the time being we will create a shim to our custom identity management solution. We'll send commands to the win2K8 vcenter server from the IDM server to create the user account and or group (if the group doesn't exist already), set the account password with what is in the maseter database, add the appropriate group membership based on the ldap user's group membership. Oh did I mention that it will be syncronized? ya that too. No we don't use Novell's IDM solution.