# AD Before Provisioning rule not working as expected

**URL:** <https://developer.sailpoint.com/discuss/t/ad-before-provisioning-rule-not-working-as-expected/55114>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, identity-security-cloud\
**Created:** [May 2, 2024, 7:09am UTC](https://developer.sailpoint.com/discuss/t/ad-before-provisioning-rule-not-working-as-expected/55114 "2024-05-02T07:09:24Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![jesvin90](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jesvin90/32/5301_2.png) [@jesvin90](https://developer.sailpoint.com/discuss/u/jesvin90)\
**Post date:** [May 2, 2024, 10:23am UTC](https://developer.sailpoint.com/discuss/t/ad-before-provisioning-rule-not-working-as-expected/55114/4 "2024-05-02T10:23:11Z")

</div>

Hi @kalyannambi2010,

If the user account is already in a disabled status, there will be no provisioning activity triggered, so you cannot modify the plan as there is no plan generated in the first place.

You will need to sync some attribute to AD (eg. employee status) as part of the user termination and then modify the plan to accommodate your changes.

Alternatively, you can make use of an aftermodify powerShell script instead of a before provisioning rule to achieve this.

Please also take a look at the below thread on making use of the Services Standard Before Provisioning Rule to achieve most of the AD use cases by making changes in the source configuration.

> [@Services Standard Before Provisioning Rule](https://developer.sailpoint.com/discuss/t/services-standard-before-provisioning-rule/20623/3):
>
> @vijaylca Here’s the code from version 1.7.1 (available in the attached ZIP file in this article [https://community.sailpoint.com/t5/Working-With-Services-Knowledge/IdentityNow-Mock-Project/ta-p/208216](https://community.sailpoint.com/t5/Working-With-Services-Knowledge/IdentityNow-Mock-Project/ta-p/208216) import sailpoint.object.Application; import sailpoint.object.Attributes; import sailpoint.object.Filter; import sailpoint.object.Identity; import sailpoint.object.ManagedAttribute.Type; import sailpoint.object.ProvisioningPlan; import sailpoint.object.ProvisioningPlan.AccountRequest; imp…

---

_[View the full topic](https://developer.sailpoint.com/discuss/t/ad-before-provisioning-rule-not-working-as-expected/55114)._
