Certification of Access Profiles Assigned Directly vs. via Roles

Hi,

Currently, our access profiles are included as part of roles, but they can also be assigned directly through the application.

In SailPoint ISC, we want to launch a certification only for identities where the access profiles are assigned directly. Any identity that has access profiles assigned through a role should not be included in this certification.

Does anyone have an idea on how to achieve this ?

After testing, when trying to certify Access Profiles, if those users have access profiles through roles, they do not appear in the certification.

Thanks.