Hi @cmoncrieff ,
Regarding removing access when an identity becomes inactive, I recommend the following approach:
This workflow generates a target certification campaign for the identity and then automatically closes the campaign by revoking all access. It also provides a complete audit trail and reporting for compliance purposes.
The Manage Access method creates multiple revoke access requests. However, if you’re trying to remove automatically assigned access or revoke identities that were added directly to a role’s identity list, this method will not work.
Regarding your specific error message: when you say the access was manually assigned, do you mean it was granted through an access request, or was the identity added directly to the Identity List of the role?