# Application assignment should be done from rule

**URL:** <https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830>\
**Category:** IIQ Discussion and Questions\
**Tags:** identityiq, applications\
**Created:** [April 24, 2024, 12:38pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830 "2024-04-24T12:38:27Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![amanKsingh](https://avatars.discourse-cdn.com/v4/letter/a/3bc359/32.png) [@amanKsingh](https://developer.sailpoint.com/discuss/u/amanKsingh)\
**Post date:** [April 24, 2024, 12:38pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830/1 "2024-04-24T12:38:27Z")

</div>

### Which IIQ version are you inquiring about?

Version 8.3

### Share all details related to your problem, including any error messages you may have received.

Hi Team,  
I have to written one rule in which I can assign application to user but I don’t want to pass attribute values through attribute request, I want that it should called provisioning policy of that application.  
If it possible, can you please share some sample.

---

<div class="post-metadata">

**Author:** ![kjakubiak](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/kjakubiak/32/7052_2.png) [@kjakubiak](https://developer.sailpoint.com/discuss/u/kjakubiak)\
**Post date:** [April 24, 2024, 12:51pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830/2 "2024-04-24T12:51:35Z")

</div>

Hi Aman,  
Sure - it’s quite easy . Actualy what you need is at least 1 attribute which should not be null. Usually it is eg. status.

With that you can just create an IT Role and assign “entitlement” as status.notNull()

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/8/8bc046749f77b04668d5bd8734eb79b5d9c6a65a.png)

This will result in CREATE provisioning transaction whenever identity which got this IT Role does not have at least account with not null status attribute. And than in CREATE provisioning policy you can set all neccesary attributes.

---

<div class="post-metadata">

**Author:** ![amanKsingh](https://avatars.discourse-cdn.com/v4/letter/a/3bc359/32.png) [@amanKsingh](https://developer.sailpoint.com/discuss/u/amanKsingh)\
**Post date:** [April 24, 2024, 2:44pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830/3 "2024-04-24T14:44:43Z")

</div>

@kjakubiak, Thank you for your reply.  
I have below rule in which two attributes I want to passthrough via AttributeRequest as mentioned in code and other Attributes I want through provisioning policy.

If this is a possible scenario then please guide me

```auto
type or paste code here

  import sailpoint.object.ProvisioningPlan;

  import sailpoint.object.ProvisioningPlan.AccountRequest;

  import sailpoint.object.ProvisioningPlan.AttributeRequest;      

  import sailpoint.object.Identity; 

  import java.util.List;

  import java.util.ArrayList;                        
 
  ProvisioningPlan plan = new ProvisioningPlan();          

  String identityName="NQABC123";

  Identity identityObject = context.getObjectByName(Identity.class, identityName);

  log.debug("Employee... Create plan.");                                       

  List accreqs = new ArrayList();                                   
 
  //create AD account
 
  AccountRequest acctReq = new AccountRequest();

  acctReq.setOperation(AccountRequest.Operation.Create);

  acctReq.setApplication("AD");
 
  acctReq.add(new AttributeRequest("sAMAccountName",identityName));

  acctReq.add(new AttributeRequest("*password*","newP@$$word"));              
 
  accreqs.add(acctReq);

  plan.setAccountRequests(accreqs);

  plan.setIdentity(identityObject);

  System.out.println("Plan = " + plan.toXml());

  return plan;

```

---

<div class="post-metadata">

**Author:** ![kjakubiak](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/kjakubiak/32/7052_2.png) [@kjakubiak](https://developer.sailpoint.com/discuss/u/kjakubiak)\
**Post date:** [April 24, 2024, 2:48pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830/4 "2024-04-24T14:48:52Z")

</div>

> [@amanKsingh](#):
>
> s a possible scenario then please g

You can just define them in the provisioning policy or add to the provisioning plan in the before provisioning rule I would say.

---

<div class="post-metadata">

**Author:** ![amanKsingh](https://avatars.discourse-cdn.com/v4/letter/a/3bc359/32.png) [@amanKsingh](https://developer.sailpoint.com/discuss/u/amanKsingh)\
**Post date:** [April 24, 2024, 3:41pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830/5 "2024-04-24T15:41:20Z")

</div>

@kjakubiak, Can you please share some example code snipped of before provisioning rule.

---

<div class="post-metadata">

**Author:** ![ajmerasunny1](https://avatars.discourse-cdn.com/v4/letter/a/3be4f8/32.png) [@ajmerasunny1](https://developer.sailpoint.com/discuss/u/ajmerasunny1)\
**Post date:** [April 24, 2024, 3:51pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830/6 "2024-04-24T15:51:53Z")

</div>

here is a sample rule that you refer

```auto
import sailpoint.object.*;
import sailpoint.object.Filter;
import sailpoint.object.ProvisioningPlan;
import sailpoint.object.ProvisioningPlan.AccountRequest;
import sailpoint.object.ProvisioningPlan.AttributeRequest;
import sailpoint.object.ProvisioningPlan.Operation;
import sailpoint.object.ManagedAttribute;
import sailpoint.object.QueryOptions;

List accReqs = plan.getAccountRequests();
if ((accReqs != null) && (accReqs.size() > 0)) {
	for(AccountRequest accReq : accReqs) {

	String val1 = "TestLDAPAttribute";
	System.out.println("val1 = " + val1);

	List attrReqs = accReq.getAttributeRequests();
		if ((attrReqs != null) && (attrReqs.size() > 0)) {
		for(AttributeRequest attrReq : attrReqs) {
		System.out.println("In the for loop");
		   String val = attrReq.getName();
		   System.out.println("val = " + val);
		   if(val.equalsIgnoreCase(val1)){
			   System.out.println("Found " + val1);
				AttributeRequest newAttReq = new AttributeRequest();
				newAttReq.setOperation(ProvisioningPlan.Operation.Add);
				newAttReq.setName("objectClass");
				newAttReq.setValue("TestLDAPobjectClass");
				accReq.add(newAttReq);
    }
	break;
   }
  }
 }
}

```

---

<div class="post-metadata">

**Author:** ![amanKsingh](https://avatars.discourse-cdn.com/v4/letter/a/3bc359/32.png) [@amanKsingh](https://developer.sailpoint.com/discuss/u/amanKsingh)\
**Post date:** [April 25, 2024, 12:11pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830/7 "2024-04-25T12:11:35Z")

</div>

@ajmerasunny1 As per my above code can we pass provisioning policy in plan itself.

---

<div class="post-metadata">

**Author:** ![rajeshs](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@rajeshs](https://developer.sailpoint.com/discuss/u/rajeshs)\
**Post date:** [April 25, 2024, 1:10pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830/8 "2024-04-25T13:10:30Z")

</div>

Hi @amanKsingh  
Based on what I understand from your requirement is that.

1. need to create attribute via provisioning plan
2. need to pass attribute from the provisioning policy to the provisioning plan

I don’t think you will be able to pass it to the plan directly. Instead you can create a beforeProvisioning Rule and pass the attributes there

---

<div class="post-metadata">

**Author:** ![vishal\_kejriwal1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vishal_kejriwal1/32/10904_2.png) [@vishal\_kejriwal1](https://developer.sailpoint.com/discuss/u/vishal_kejriwal1)\
**Post date:** [April 25, 2024, 4:58pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830/9 "2024-04-25T16:58:12Z")

</div>

You can also try using the dummy entitlement , When you trying add the dummy entailment either through role / access request page . automatically system will use provisioning policy and will try to populate all the required value and ppulate the attribute request and then in before provisioning rule you can remove added dummy entitlement .

---

<div class="post-metadata">

**Author:** ![rajeshs](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@rajeshs](https://developer.sailpoint.com/discuss/u/rajeshs)\
**Post date:** [April 25, 2024, 5:19pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830/10 "2024-04-25T17:19:13Z")

</div>

Good alternative approach. Thanks for sharing @vishal_kejriwal1

---

<div class="post-metadata">

**Author:** ![vishal\_kejriwal1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vishal_kejriwal1/32/10904_2.png) [@vishal\_kejriwal1](https://developer.sailpoint.com/discuss/u/vishal_kejriwal1)\
**Post date:** [April 26, 2024, 2:34pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830/11 "2024-04-26T14:34:26Z")

</div>

Thank you @rajeshs .

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [June 25, 2024, 2:35pm UTC](https://developer.sailpoint.com/discuss/t/application-assignment-should-be-done-from-rule/53830/12 "2024-06-25T14:35:01Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
