(ITS#7091) Limit ppolicy_forward_updates

This is a feature request:
It should be possible to limit effect of ppolicy_forward_updates to certain
events like. Maybe just a list of attributes which should be forwarded to a
Rationale: To reduce the load on the provide one might want to only forward
lockouts to the provider and not each login failure.