# Problem with Revoke entitlement operation in Webservice connector

**URL:** <https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615>\
**Category:** SHF Discussion and Questions\
**Tags:** webservice-connector, connectors, sources, provisioning, certifications, identity-security-cloud, apis, rules, aggregation, entitlements\
**Created:** [August 22, 2024, 8:44am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615 "2024-08-22T08:44:01Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![sethi\_shivam](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@sethi\_shivam](https://developer.sailpoint.com/discuss/u/sethi_shivam)\
**Post date:** [August 22, 2024, 8:44am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/1 "2024-08-22T08:44:01Z")

</div>

Hi team ,

I am configured a webservice connector for my Target system .

and written a custom before provisioning rule to change Disable operation to Delete operation

so that If IDN doesn’t show me disabled status .

but when I am trying to create a certification campaign and revoking an entitlement.

The entitlement and AP is removed from user profile in IDN but account is still present there . When I am checking the target system the user is not present .

Now the problem coming is , when I am trying to raise request again for the same AP it is throwing error saying :

Exception while updating account.Url: **Message: 404 : Not Found, HTTP Error Code: 404**

NOTE : Aggregation is scheduled after every 6 hours and this is happening when I am trying within this 6 hours window.

and also I checked the sailpoint documentation , there is no operation present for “REVOKE” functionality  
there are only operations present for  
**Delete**  
**Disable**  
**Enable**  
**Lock**  
**Unlock**

Could someone please help me If I can write custom code for REVOKE so that if someone triggers the revoke event than it automatically delete the account as well .

or if there is any other way to fix it

Best Regards

---

<div class="post-metadata">

**Author:** ![shekhardas1825](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/shekhardas1825/32/20889_2.png) [@shekhardas1825](https://developer.sailpoint.com/discuss/u/shekhardas1825)\
**Post date:** [August 22, 2024, 8:57am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/2 "2024-08-22T08:57:59Z")

</div>

@sethi_shivam Please check your remove entitlement operation, are you deleting the account there? or just removing the requested entitlement?

If you are deleting the account then it is obvious that account is getting deleted in target system but For IDN it is just a entitlement remove request and that is the reason you see the account still present and when you request any access for that account it does not find in the target.

So if I understood correctly:

1. In the event of disable account you simply want to delete the account.
2. When you want to remove / revoke entitlement (either it via access request or Certification) you just want to remove the entitlement from the account. (In this case you just need to make sure you configure remove entitlement operation and make sure you are calling correct API which just removes the entitlement)
3. If in case you want account to be deleted when you request for remove entitlement then you will have to use Before Provisioning rule change the Operation to delete(after checking attribute request) like you are doing for Disable.

Regards,  
Shekhar Das

---

<div class="post-metadata">

**Author:** ![sethi\_shivam](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@sethi\_shivam](https://developer.sailpoint.com/discuss/u/sethi_shivam)\
**Post date:** [August 22, 2024, 9:13am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/3 "2024-08-22T09:13:13Z")

</div>

HI @shekhardas1825 yes you are right but for the 2nd point … when I am revoking the entitlement , I also want to delete the account .

but now there is one more thing , I also need to check that it should not be revoked he there are still some entitlements present .

---

<div class="post-metadata">

**Author:** ![shekhardas1825](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/shekhardas1825/32/20889_2.png) [@shekhardas1825](https://developer.sailpoint.com/discuss/u/shekhardas1825)\
**Post date:** [August 22, 2024, 9:20am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/4 "2024-08-22T09:20:29Z")

</div>

@sethi_shivam I did not get the second para of your second post.

As I mentioned in my first reply point number 3, If in case you want account to be deleted when you request for remove entitlement then you will have to use Before Provisioning rule change the Operation to delete (after checking attribute request) like you are doing for Disable.

Check Modify Operation (ProvisioningPlan.AccountRequest.Operation.Modify)  
Check Attribute request (for e.g. you marked attribute “group” as entitlment in your account schema) check group is being requested for remove  
Check Operation is remove(sailpoint.object.ProvisioningPlan.Operation.Remove)  
if yes then change the operation to DELETE

---

<div class="post-metadata">

**Author:** ![sethi\_shivam](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@sethi\_shivam](https://developer.sailpoint.com/discuss/u/sethi_shivam)\
**Post date:** [August 22, 2024, 9:27am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/5 "2024-08-22T09:27:48Z")

</div>

![2024-08-22_11-26](https://global.discourse-cdn.com/sailpoint/original/2X/c/c4fffdfe7c6cadd10dd9afb952fae38d063e2a33.png)

this is my piece of code which I am using for Before provisioning rule

---

<div class="post-metadata">

**Author:** ![sethi\_shivam](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@sethi\_shivam](https://developer.sailpoint.com/discuss/u/sethi_shivam)\
**Post date:** [August 22, 2024, 9:29am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/6 "2024-08-22T09:29:19Z")

</div>

So I am using this as before provisioning rule and calling delete operation for disabled operation and remove operation … but for Revoke operation i didn;t find anything

---

<div class="post-metadata">

**Author:** ![shekhardas1825](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/shekhardas1825/32/20889_2.png) [@shekhardas1825](https://developer.sailpoint.com/discuss/u/shekhardas1825)\
**Post date:** [August 22, 2024, 9:43am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/7 "2024-08-22T09:43:09Z")

</div>

There is no such operation called Revoke. Please check my second reply I have updated it.

---

<div class="post-metadata">

**Author:** ![shekhardas1825](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/shekhardas1825/32/20889_2.png) [@shekhardas1825](https://developer.sailpoint.com/discuss/u/shekhardas1825)\
**Post date:** [August 22, 2024, 9:54am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/8 "2024-08-22T09:54:22Z")

</div>

Ok, Do you want to say you want to delete Account only if there will be no entitlement left ?

In that case you can write a method to get all his existing access keep it in a list  
Get requested access to be removed and remove that from existing list.  
Check if the list is empty if yes then change the operation to DELETE if no just do nothing. (all these can be done in BP rule)

---

<div class="post-metadata">

**Author:** ![sethi\_shivam](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@sethi\_shivam](https://developer.sailpoint.com/discuss/u/sethi_shivam)\
**Post date:** [August 22, 2024, 10:33am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/9 "2024-08-22T10:33:04Z")

</div>

Yes , I am thinking the same and I need to update the BP and really thanks for the help

---

<div class="post-metadata">

**Author:** ![jesvin90](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jesvin90/32/5301_2.png) [@jesvin90](https://developer.sailpoint.com/discuss/u/jesvin90)\
**Post date:** [August 22, 2024, 2:53pm UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/10 "2024-08-22T14:53:55Z")

</div>

Hi @sethi_shivam,

You may also want to take a look at the Entitlement Cardinality trigger in the Services Standard BeforeProvisioning Rule which can serve your use case here.

[Services Standard IdentityNow BeforeProvisioning Rule - README.pdf](https://developer.sailpoint.com/discuss/uploads/short-url/jzXCkhlWUE5tJaFEckgCgULAa0y.pdf) (68.5 KB)

---

<div class="post-metadata">

**Author:** ![sethi\_shivam](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@sethi\_shivam](https://developer.sailpoint.com/discuss/u/sethi_shivam)\
**Post date:** [September 2, 2024, 2:44pm UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/11 "2024-09-02T14:44:34Z")

</div>

HI @jesvin90

thanks for the response and I am using this

condition  
{  
“Attribute”: “groups”,  
“Value”: null,  
“Operation”: “LastRemoved”  
}

but I am not sure about these 2 things

1. _“Attribute”: “groups”_ what to write instead of groups
2. from where I can find the value of **“Attribute”:** in my environment

thanks

---

<div class="post-metadata">

**Author:** ![shekhardas1825](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/shekhardas1825/32/20889_2.png) [@shekhardas1825](https://developer.sailpoint.com/discuss/u/shekhardas1825)\
**Post date:** [September 2, 2024, 3:02pm UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/12 "2024-09-02T15:02:36Z")

</div>

@sethi_shivam It’s the account attribute, you just need to replace with the attribute which you marked as entitlement in your account schema.

For example if you marked **role** as entitlement it will look like

```auto

"Entitlement Cardinality Update Triggers":[
 {
 "Attribute":"role",
 "Operation":"LastRemoved",
 "Value": null
 }
]

```

For example if you marked **AuthorityProfile** as entitlement it will look like

```auto

"Entitlement Cardinality Update Triggers":[
 {
 "Attribute":"AuthorityProfile",
 "Operation":"LastRemoved",
 "Value": null
 }
]

```

---

<div class="post-metadata">

**Author:** ![sethi\_shivam](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@sethi\_shivam](https://developer.sailpoint.com/discuss/u/sethi_shivam)\
**Post date:** [September 2, 2024, 3:31pm UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/13 "2024-09-02T15:31:37Z")

</div>

@shekhardas1825

thanks for responding ,

```
    "cloudServicesIDNSetup": {
        "eventConfigurations": [
            {
                "eventActions": [
                    {
                        "Action": "ChangeOperation",
                        "Attribute": null,
                        "Value": "Delete"
                    }
                ],
                "Identity Attribute Triggers": [
                    {
                        "Attribute": "cloudLifecycleState",
                        "Value": "inactive",
                        "Operation": "eq"
                    }
                ],
                "Operation": "Disable",
                "Entitlement Cardinality Update Triggers": [
                    {
                        "Attribute": "role",
                        "Value": null,
                        "Operation": "LastRemoved"
                    }
                ]
            }
        ]
    }, 

```

I am using this condition but still when I revoked an entitlement (for eg : ABC)  
and visit the user profile again , it shows me that account is still there  
and under entitlements /Access profiles , it doesnt show me anything .

Now when I am requesting the same account again (for eg : ABC) , I am getting the error that user doesnt exist on target system .

---

<div class="post-metadata">

**Author:** ![sethi\_shivam](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@sethi\_shivam](https://developer.sailpoint.com/discuss/u/sethi_shivam)\
**Post date:** [September 2, 2024, 3:32pm UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/14 "2024-09-02T15:32:48Z")

</div>

basically even after removing the last entitlement , it is still showing me the link to that target system , which should not be there , and due to which I am not able to request the same entitlement or any other entitlement again because instead of creating user , it is searching and updating user

---

<div class="post-metadata">

**Author:** ![shekhardas1825](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/shekhardas1825/32/20889_2.png) [@shekhardas1825](https://developer.sailpoint.com/discuss/u/shekhardas1825)\
**Post date:** [September 2, 2024, 3:42pm UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/15 "2024-09-02T15:42:56Z")

</div>

Can you check if your “services Standard IdentityNow BeforeProvisioning Rule” is attached to your source?

Try to de-attach and attach again.

Also make sure your delete Operation is configured.

To validate your configuration is working, you can search the user go to account activity and see if you see delete operation is triggered. Possibly you will see which operation is being called for the account.

---

<div class="post-metadata">

**Author:** ![sethi\_shivam](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@sethi\_shivam](https://developer.sailpoint.com/discuss/u/sethi_shivam)\
**Post date:** [September 3, 2024, 7:40am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/16 "2024-09-03T07:40:37Z")

</div>

HI @shekhardas1825 ,

I just saw the events and Delete operation is not getting triggered .

---

<div class="post-metadata">

**Author:** ![sethi\_shivam](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@sethi\_shivam](https://developer.sailpoint.com/discuss/u/sethi_shivam)\
**Post date:** [September 3, 2024, 8:02am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/17 "2024-09-03T08:02:30Z")

</div>

@shekhardas1825 All I can see that

Change Identity Lifecycle State Success  
Remove Entitlement Passed  
Modify Account Passed

only these tasks are getting triggered

---

<div class="post-metadata">

**Author:** ![shekhardas1825](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/shekhardas1825/32/20889_2.png) [@shekhardas1825](https://developer.sailpoint.com/discuss/u/shekhardas1825)\
**Post date:** [September 3, 2024, 8:34am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/18 "2024-09-03T08:34:22Z")

</div>

@sethi_shivam Try below:

```auto
"cloudServicesIDNSetup": {
        "eventConfigurations": [
            {
                "eventActions": [
                    {
                        "Action": "ChangeOperation",
                        "Attribute": null,
                        "Value": "Delete"
                    }
                ],
                "Identity Attribute Triggers": [
                    {
                        "Attribute": "cloudLifecycleState",
                        "Value": "inactive",
                        "Operation": "eq"
                    }
                ],
                "Entitlement Cardinality Update Triggers": [
                    {
                        "Attribute": "role",
                        "Value": null,
                        "Operation": "LastRemoved"
                    }
                ],
				"Operation": "Disable"
            }
        ]
    }

```

Make sure your “services Standard IdentityNow BeforeProvisioning Rule” is attached to your source.

---

<div class="post-metadata">

**Author:** ![sethi\_shivam](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@sethi\_shivam](https://developer.sailpoint.com/discuss/u/sethi_shivam)\
**Post date:** [September 3, 2024, 11:37am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/19 "2024-09-03T11:37:03Z")

</div>

I just tested it , still the same issue .

---

<div class="post-metadata">

**Author:** ![shekhardas1825](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/shekhardas1825/32/20889_2.png) [@shekhardas1825](https://developer.sailpoint.com/discuss/u/shekhardas1825)\
**Post date:** [September 3, 2024, 11:55am UTC](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615/20 "2024-09-03T11:55:15Z")

</div>

Did you update the “inactive” LCS to disable the source account?

Identity Management → IdentityProfiles → Select your Identity Profile → Provisioning → Inactive

Add your source here:

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/e/6/e6476aa5f6baa41d1ef7104187476741a64de2a9.png)

[Next page](https://developer.sailpoint.com/discuss/t/problem-with-revoke-entitlement-operation-in-webservice-connector/77615.md?page=2)
