# Remove access from workflow

**URL:** <https://developer.sailpoint.com/discuss/t/remove-access-from-workflow/6220>\
**Category:** SHF Discussion and Questions\
**Tags:** workflows, identity-security-cloud, roles\
**Created:** [October 12, 2022, 4:46pm UTC](https://developer.sailpoint.com/discuss/t/remove-access-from-workflow/6220 "2022-10-12T16:46:23Z")\
**Posts on this page:** 5\
**Page:** 2

<div class="post-metadata">

**Author:** ![colin\_mckibben](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/colin_mckibben/32/37182_2.png) [@colin\_mckibben](https://developer.sailpoint.com/discuss/u/colin_mckibben)\
**Post date:** [November 1, 2022, 6:34pm UTC](https://developer.sailpoint.com/discuss/t/remove-access-from-workflow/6220/21 "2022-11-01T18:34:34Z")

</div>

Actually, I think I can tell which role is causing it from the error. The role “EXT-TestAADRole3” can’t be removed from the identity ID ending in “486”. You could even try submitting this access request from the IDN request center for just that identity and that role and see what happens.

---

<div class="post-metadata">

**Author:** ![gauravsajwan1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gauravsajwan1/32/7856_2.png) [@gauravsajwan1](https://developer.sailpoint.com/discuss/u/gauravsajwan1)\
**Post date:** [November 3, 2022, 12:56pm UTC](https://developer.sailpoint.com/discuss/t/remove-access-from-workflow/6220/22 "2022-11-03T12:56:46Z")

</div>

Hi @colin_mckibben - thanks for looking into this.

I’ve figured out the problem, so I was actually adding identities to roles using direct role assignment and revoking roles from identities using IDN Workflow (which like you said uses Access Request APIs), and that’s why we saw bad request error.

Whereas adding and revoking roles to/from identities using Access Request API and IDN workflow worked!

Thanks again mate! 🙂

---

<div class="post-metadata">

**Author:** ![colin\_mckibben](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/colin_mckibben/32/37182_2.png) [@colin\_mckibben](https://developer.sailpoint.com/discuss/u/colin_mckibben)\
**Post date:** [November 15, 2022, 2:13pm UTC](https://developer.sailpoint.com/discuss/t/remove-access-from-workflow/6220/23 "2022-11-15T14:13:40Z")

</div>

A post was split to a new topic: [How to remove birthright roles using Workflows](https://developer.sailpoint.com/discuss/t/how-to-remove-birthright-roles-using-workflows/6746)

---

<div class="post-metadata">

**Author:** ![2135797](https://avatars.discourse-cdn.com/v4/letter/2/8797f3/32.png) [@2135797](https://developer.sailpoint.com/discuss/u/2135797)\
**Post date:** [July 11, 2023, 10:53am UTC](https://developer.sailpoint.com/discuss/t/remove-access-from-workflow/6220/24 "2023-07-11T10:53:33Z")

</div>

Hi Team,  
I am also building similar workflow to remove accessprofiles to identites. Here I need to remove accessprofiles only which follows specific pattern from list of accessprofiles identity has.  
eg: identity has some 3 access profiles  
1.Black: approver-p-task  
2.prop: financial  
3.Black:approver-p-task  
here I need to remove accessprofiles which follows this pattern starts with “Black” and contain substring “-p-”  
I tried using GET ACCESS and MANAGE ACCESS but not achieved can anyone suggest any ways to achieve by using workflows.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [September 9, 2023, 10:54am UTC](https://developer.sailpoint.com/discuss/t/remove-access-from-workflow/6220/25 "2023-09-09T10:54:14Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.

[Previous page](https://developer.sailpoint.com/discuss/t/remove-access-from-workflow/6220.md?page=1)
