Remove manually assigned Active directory groups

Share all details about your problem, including any error messages you may have received.

We are working on a SailPoint IdentityIQ Leaver process to remove manually assigned entitlements to identities, mostly are Active Directory groups

What should be the best way to remove them as they don’t remain as sticky entitlements? and to avoid being provisionned again

Best regards

@alshahim04

On the basis of attributeAssignments you can add plan in leaver. So manually assigned ent will get removed.

Hi @sukarande
Thank you for your answer , is there any valuable example ?

I’am using this code to retive the remaining entitlements :

Iterator it = context.search(IdentityEntitlement.class,Filter.eq("identity.name",identity.getName())
);

then build the plan , and it executes the provisionning remove request,

When checking the link ( active directory for example ) the entiliement is removed , but on the identity i still get this :

When checking the administration console , the request is executed correctly

Thanks

QueryOptions qo = new QueryOptions();
qo.addFilter(Filter.eq(“identity.name”, identity.getName()));
qo.addFilter(Filter.eq(“application.name”, “AD Application which is as per your project”));

Iterator it = context.search(IdentityEntitlement.class, qo);

while (it != null && it.hasNext())
{
IdentityEntitlement ent = (IdentityEntitlement) it.next();

	//from here you can add your logic
	//alshahim alshahim - Please try this code

}

Hi since the entitlement is removed from the AD account but still appears as Source = Assignment, it may be a leftover AttributeAssignment (sticky entitlement).

You may find this SailPoint article helpful:

Remove unused attribute assignments for an identity to stop auto provisioning discrepancies or errors during refresh

It explains how sticky entitlements can remain on the Identity even after the entitlement is removed from the account, causing them to be re-provisioned during Identity Refresh. The article also provides a cleanup rule that can be used as a Pre-Refresh Rule or Rule Runner Task to remove orphaned AttributeAssignments.

Hope it helps.