When user name has upper case letters in LDAP kolabd treats whose users as new and sets acls. That resets acls at every LDAP synchronization as LDAP user name is not the same as it ends up being set in IMAP.
I would move lowercasing before for, so it's not done on every iteration.
I would move _folder initialization before try. Otherwise if that fails _folder might be unset. Probably not very likely scenario, but still.
Something's wrong with indentation here.