# AD Account Create

**URL:** <https://developer.sailpoint.com/discuss/t/ad-account-create/81157>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, identity-security-cloud\
**Created:** [September 13, 2024, 1:13pm UTC](https://developer.sailpoint.com/discuss/t/ad-account-create/81157 "2024-09-13T13:13:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![PhilRawlings1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/philrawlings1/32/37266_2.png) [@PhilRawlings1](https://developer.sailpoint.com/discuss/u/PhilRawlings1)\
**Post date:** [September 13, 2024, 1:13pm UTC](https://developer.sailpoint.com/discuss/t/ad-account-create/81157/1 "2024-09-13T13:13:34Z")

</div>

Hi all,

Really simple question that I can’t find a definitive answer for:  
During the AD account create process, can you add entitlements?

I’m currently using an afterCreate connector rule, but the IQ service is struggling with the number of PS instances that get spun up  
Thanks

---

<div class="post-metadata">

**Author:** ![ashutosh08](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/ashutosh08/32/11459_2.png) [@ashutosh08](https://developer.sailpoint.com/discuss/u/ashutosh08)\
**Post date:** [September 13, 2024, 1:22pm UTC](https://developer.sailpoint.com/discuss/t/ad-account-create/81157/2 "2024-09-13T13:22:42Z")

</div>

Hi @PhilRawlings1,

ISC default behavior is to create account only via access assignment i.e. you account is created only if your access is being provisioned.

Let me know if there is something specific you are looking that I am missing.

Thanks

---

<div class="post-metadata">

**Author:** ![gourab](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gourab/32/18650_2.png) [@gourab](https://developer.sailpoint.com/discuss/u/gourab)\
**Post date:** [September 13, 2024, 1:24pm UTC](https://developer.sailpoint.com/discuss/t/ad-account-create/81157/3 "2024-09-13T13:24:26Z")

</div>

Hi @PhilRawlings1 ,  
ISC will create account whenever there is access req or auto role assignment.You can use

1. Access request for Access profiles/Roles(with multiple entitlements).
2. Based on LCS you can also add access profiles on identity profile config section to add entitlements on AD.

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/5/b/5be47680115f4b649e4521e56534f7e02d6a9dd5.png)

---

<div class="post-metadata">

**Author:** ![PhilRawlings1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/philrawlings1/32/37266_2.png) [@PhilRawlings1](https://developer.sailpoint.com/discuss/u/PhilRawlings1)\
**Post date:** [September 13, 2024, 1:48pm UTC](https://developer.sailpoint.com/discuss/t/ad-account-create/81157/4 "2024-09-13T13:48:37Z")

</div>

Hi,  
The question is whether ISC can add entitlements during the create process.  
I need to add entitlements to an account based upon variables which are identity attributes.  
I can’t use Roles/profiles as there are over 12,000 different variations and you can’t use variables in Roles.  
I am using the afterCreate rule to spin up a PS script to assign the groups based upon extension attributes.  
This works fine for low volumes, but fails when the number hits 20+ instances of Powershell. I’m expecting 150+ account creates to be happening at any one moment.  
The issue is with the scaling. I can increase the specs of the computer (but there is an ongoing cost to that.  
If I can use the account Create process to add entitlements at the same time, I bypass the problem.

Is that any clearer, I want to add entitlements to a user, whose naming conventions is based upon identity attributes during the CREATE account process

NB. I’m still going to have a problem with afterModify spinning up too many instances of Powershell, but that is a different problem

---

<div class="post-metadata">

**Author:** ![PhilRawlings1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/philrawlings1/32/37266_2.png) [@PhilRawlings1](https://developer.sailpoint.com/discuss/u/PhilRawlings1)\
**Post date:** [September 13, 2024, 3:11pm UTC](https://developer.sailpoint.com/discuss/t/ad-account-create/81157/5 "2024-09-13T15:11:05Z")

</div>

Many thanks to @gourab for pointing me in the correct direction:  
For future people, you can add entitlements during the create process using identity attributes and transforms as variables:

```auto
        {
            "name": "memberOf",
            "transform": {
                "type": "static",
                "attributes": {
                    "value": "CN=$value $name,OU=Groups,OU=$value,OU=$type,OU=abc,DC=def,DC=com",
                    "value": {
                        "type": "identityAttribute",
                        "attributes": {
                            "name": "name"
                        }
                    },
                    "name": {
                        "type": "identityAttribute",
                        "attributes": {
                            "name": "name1"
                        }
                    },
                    "type": {
                        "type": "reference",
                        "attributes": {
                            "id": "type"
                        }
                    }
                }
            },
            "attributes": {},
            "isRequired": false,
            "type": "string",
            "isMultiValued": true
        }

```

Just add the above to the CREATE file

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [November 12, 2024, 3:11pm UTC](https://developer.sailpoint.com/discuss/t/ad-account-create/81157/6 "2024-11-12T15:11:43Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
