How can entitlements be revoked after a user is terminated when those entitlements were not provisioned through SailPoint? The entitlements are assigned directly at the endpoint level. For example, in Microsoft Entra ID, many application roles and group memberships are assigned directly within the application rather than through SailPoint. I explored implementing this through a workflow, but it does not appear to be a feasible solution due to the loop limitations within SailPoint workflows.
Please consider addressing the following when creating your topic:
- What have you tried?
- What errors did you face (share screenshots)?
- Share the details of your efforts (code / search query, workflow json etc.)?
- What is the result you are getting and what were you expecting?

