Hi Guillaume,
Can you check the privilege tab on repository and confirm the PRIV:DE2:ONLY is mapped as the master privilege ?
If the PRIV:<>:ONLY is mapped as master privilege on repository, then the account attribute is created for the user on the repository.
If any other privileges of same repository are assigned, firstly IDM checks whether the account attribute exists for the user for the repository or not. If account attribute is not available, the assignments will get failed. this is what happening in your case.
All the best !!
~ Krishna.