agree with @drosenbauer
I haven’t used Workflow approach yet, that’s a very good approach.
I have done simple implementation using AD Groups, you can refer this topic and find my response there.
On Premise Exchange Setup - IdentityNow (IDN) / Discussion and Questions - SailPoint Developer Community Forum