# AD Entitlement Provisioning to Inactive Identities

**URL:** <https://developer.sailpoint.com/discuss/t/ad-entitlement-provisioning-to-inactive-identities/14773>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, access-requests, identity-security-cloud, entitlements\
**Created:** [July 20, 2023, 9:55pm UTC](https://developer.sailpoint.com/discuss/t/ad-entitlement-provisioning-to-inactive-identities/14773 "2023-07-20T21:55:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![johnpaul\_tran](https://avatars.discourse-cdn.com/v4/letter/j/e0b2c6/32.png) [@johnpaul\_tran](https://developer.sailpoint.com/discuss/u/johnpaul_tran)\
**Post date:** [July 20, 2023, 9:55pm UTC](https://developer.sailpoint.com/discuss/t/ad-entitlement-provisioning-to-inactive-identities/14773/1 "2023-07-20T21:55:57Z")

</div>

Hello All -

I’ve noticed that IDN will continue to add AD entitlements that were requested via request center (sticky entitlements) to inactive identities if the entitlement is removed from the source account. What’s concerning is that if the AD account is deleted, IDN will recreated the AD user object in an active state and add the entitlement, despite an inactive LCS. I hope this is not the expected behavior?? How do we get IDN to release the sticky entitlements to prevent this?

---

<div class="post-metadata">

**Author:** ![atarodia](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@atarodia](https://developer.sailpoint.com/discuss/u/atarodia)\
**Post date:** [July 21, 2023, 11:56am UTC](https://developer.sailpoint.com/discuss/t/ad-entitlement-provisioning-to-inactive-identities/14773/2 "2023-07-21T11:56:34Z")

</div>

Hi @johnpaul_tran,

You can create a workflow to remove those sticky entitlements.

There is currently no good and best way to find out which ones are sticky but you could use the “[Completed Access Request Approval API](https://developer.sailpoint.com/idn/api/beta/list-completed-approvals)” to get list of all entilement approvals. (Entitlement Request Approval should be enabled) and then in a `loop operator`, you call [Entitlement Revoke API](https://developer.sailpoint.com/idn/api/beta/create-access-request/) to get rid of sticky entitlement.

Another option is to write a BeforeProvisioningRule to remove the sticky assignment.

---

<div class="post-metadata">

**Author:** ![johnpaul\_tran](https://avatars.discourse-cdn.com/v4/letter/j/e0b2c6/32.png) [@johnpaul\_tran](https://developer.sailpoint.com/discuss/u/johnpaul_tran)\
**Post date:** [July 21, 2023, 2:20pm UTC](https://developer.sailpoint.com/discuss/t/ad-entitlement-provisioning-to-inactive-identities/14773/3 "2023-07-21T14:20:11Z")

</div>

Thank you for the response @atarodia. I have am in the process of reviewing the video found here: [Ungluing Sticky AttributeAssignments](https://developer.sailpoint.com/discuss/t/ungluing-sticky-attributeassignments/8166) however this is for IIQ. I assume the BeforeProvisioningRule option you mentioned is similar to what is discussed in the video but searching Compass, I do not see any reference to AttributeAssignment for IDN. Do you know if this is also applicable for IDN?

---

<div class="post-metadata">

**Author:** ![justinrhaines](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/justinrhaines/32/16564_2.png) [@justinrhaines](https://developer.sailpoint.com/discuss/u/justinrhaines)\
**Post date:** [July 21, 2023, 3:54pm UTC](https://developer.sailpoint.com/discuss/t/ad-entitlement-provisioning-to-inactive-identities/14773/4 "2023-07-21T15:54:34Z")

</div>

I have also seen this behavior. You can also use a certification to revoke the entitlement which will remove the tape for the sticky entitlement. Hope that helps!.

---

<div class="post-metadata">

**Author:** ![johnpaul\_tran](https://avatars.discourse-cdn.com/v4/letter/j/e0b2c6/32.png) [@johnpaul\_tran](https://developer.sailpoint.com/discuss/u/johnpaul_tran)\
**Post date:** [July 21, 2023, 4:59pm UTC](https://developer.sailpoint.com/discuss/t/ad-entitlement-provisioning-to-inactive-identities/14773/5 "2023-07-21T16:59:10Z")

</div>

We are looking for an automated solution without having to trigger a certification on an inactive LCS and requiring someone to manually revoke the entitlments.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [September 19, 2023, 5:00pm UTC](https://developer.sailpoint.com/discuss/t/ad-entitlement-provisioning-to-inactive-identities/14773/6 "2023-09-19T17:00:04Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
