# Remove Entitlement post Disable user operation

**URL:** <https://developer.sailpoint.com/discuss/t/remove-entitlement-post-disable-user-operation/57730>\
**Category:** SHF Discussion and Questions\
**Tags:** webservice-connector, developer-days-2023-idn, apis, identity-security-cloud\
**Created:** [May 23, 2024, 8:36am UTC](https://developer.sailpoint.com/discuss/t/remove-entitlement-post-disable-user-operation/57730 "2024-05-23T08:36:59Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sgupta1](https://avatars.discourse-cdn.com/v4/letter/s/779978/32.png) [@Sgupta1](https://developer.sailpoint.com/discuss/u/Sgupta1)\
**Post date:** [May 23, 2024, 8:36am UTC](https://developer.sailpoint.com/discuss/t/remove-entitlement-post-disable-user-operation/57730/1 "2024-05-23T08:36:59Z")

</div>

Hi Everyone,  
We have integrated a web service connector. We need to remove the entitlement assigned to the user once user is disabled from the source. Web Service connector is having http operation of Remove entitlement but that is not getting called once user is disabled.

We also tried writing Before Operation rule to remove the entitlements but we are getting NULL value using provisioningPlan.getNativeIdentity().

Please suggest some workaround for this requirement.

Thanks

---

<div class="post-metadata">

**Author:** ![jesvin90](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jesvin90/32/5301_2.png) [@jesvin90](https://developer.sailpoint.com/discuss/u/jesvin90)\
**Post date:** [May 23, 2024, 8:47am UTC](https://developer.sailpoint.com/discuss/t/remove-entitlement-post-disable-user-operation/57730/2 "2024-05-23T08:47:00Z")

</div>

Hi @Sgupta1,

Have you taken a look into the Services Standard Before Provisioning [Rule](https://developer.sailpoint.com/discuss/t/services-standard-before-provisioning-rule/20623/3) .?

You can make use of the remove entitlements action to remove the user entitlements as part of the disable operation. Take a look at the attached documentation for more details.

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/7/70fbf723065e4a4a66c9ce028ff1c4f89bce0045.png)

[Services Standard IdentityNow BeforeProvisioning Rule - README.pdf](https://developer.sailpoint.com/discuss/uploads/short-url/jzXCkhlWUE5tJaFEckgCgULAa0y.pdf) (68.5 KB)

---

<div class="post-metadata">

**Author:** ![KirstenV](https://avatars.discourse-cdn.com/v4/letter/k/278dde/32.png) [@KirstenV](https://developer.sailpoint.com/discuss/u/KirstenV)\
**Post date:** [May 23, 2024, 9:46am UTC](https://developer.sailpoint.com/discuss/t/remove-entitlement-post-disable-user-operation/57730/3 "2024-05-23T09:46:31Z")

</div>

What operation type is the remove entitlement operation set to? Have you tried setting it to the “Disable Account” operation type?  
That way it should be called during the disable operation as well.

---

<div class="post-metadata">

**Author:** ![ipobeidi](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/ipobeidi/32/16000_2.png) [@ipobeidi](https://developer.sailpoint.com/discuss/u/ipobeidi)\
**Post date:** [May 23, 2024, 4:55pm UTC](https://developer.sailpoint.com/discuss/t/remove-entitlement-post-disable-user-operation/57730/4 "2024-05-23T16:55:01Z")

</div>

Just create a Disable operation that is actually a remove on the api .

You can have parenting on Disable if i’m not mistaken

---

<div class="post-metadata">

**Author:** ![schattopadhy](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/schattopadhy/32/8854_2.png) [@schattopadhy](https://developer.sailpoint.com/discuss/u/schattopadhy)\
**Post date:** [May 24, 2024, 4:21am UTC](https://developer.sailpoint.com/discuss/t/remove-entitlement-post-disable-user-operation/57730/5 "2024-05-24T04:21:21Z")

</div>

@Sgupta1 these can you tell how these entitlement are being granted is it via access request or birth right?.

If via access request then you can go with the below options  
1- Write a before rule for removal  
2-Go for a workflow to remove on identity attribute lifecycle state change  
3-Certification on such users can remove access

Thanks  
Shantanu

---

<div class="post-metadata">

**Author:** ![Karthikeyan\_U](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/karthikeyan_u/32/23649_2.png) [@Karthikeyan\_U](https://developer.sailpoint.com/discuss/u/Karthikeyan_U)\
**Post date:** [May 24, 2024, 7:45am UTC](https://developer.sailpoint.com/discuss/t/remove-entitlement-post-disable-user-operation/57730/6 "2024-05-24T07:45:41Z")

</div>

> [@Sgupta1](#):
>
> We need to remove the entitlement assigned to the user once user is disabled from the source. Web Service connector is having http operation of Remove entitlement but that is not getting called once user is disabled.

Hi Shikha,

You can try adding two operations for Disable(like Disable - 1 and Disable - 2), so basically the first operation will be used to disable the user account, 2nd one can be used to remove the user entitlements (use before provisioning rule to get the user entitlements and update the jsonbody). Also make sure to have the appropriate context URL inplace for entitlement remove.

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/8/8504d9a5e60fb1e6b866ebb7220e0d4accb3d193.png)

---

<div class="post-metadata">

**Author:** ![Karthikeyan\_U](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/karthikeyan_u/32/23649_2.png) [@Karthikeyan\_U](https://developer.sailpoint.com/discuss/u/Karthikeyan_U)\
**Post date:** [May 28, 2024, 6:31pm UTC](https://developer.sailpoint.com/discuss/t/remove-entitlement-post-disable-user-operation/57730/7 "2024-05-28T18:31:13Z")

</div>

Hi @Sgupta1 ,

Was the above solution helpful and worked?

Thanks!!

---

<div class="post-metadata">

**Author:** ![Sgupta1](https://avatars.discourse-cdn.com/v4/letter/s/779978/32.png) [@Sgupta1](https://developer.sailpoint.com/discuss/u/Sgupta1)\
**Post date:** [June 18, 2024, 8:14am UTC](https://developer.sailpoint.com/discuss/t/remove-entitlement-post-disable-user-operation/57730/8 "2024-06-18T08:14:10Z")

</div>

Thanks @Karthikeyan_U this worked.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [August 17, 2024, 8:14am UTC](https://developer.sailpoint.com/discuss/t/remove-entitlement-post-disable-user-operation/57730/9 "2024-08-17T08:14:23Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
