# Removing all users Roles and Entitlements

**URL:** <https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927>\
**Category:** IIQ Discussion and Questions\
**Tags:** identityiq, lifecycle-management, workflows, rules\
**Created:** [December 10, 2024, 2:43pm UTC](https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927 "2024-12-10T14:43:06Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![d\_pustovoitov](https://avatars.discourse-cdn.com/v4/letter/d/46a35a/32.png) [@d\_pustovoitov](https://developer.sailpoint.com/discuss/u/d_pustovoitov)\
**Post date:** [December 10, 2024, 2:43pm UTC](https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927/1 "2024-12-10T14:43:07Z")

</div>

## Which IIQ version are you inquiring about?

8.3p3

Hello everyone!

I hope someone had the next use case with the IIQ and can help me with the next question.

We want to use the following workflow in our environment for the Mover Lifecycle Event: 1. After the event is triggered, all user roles should be removed → 2. All user entitlements should be removed → 3. The new entitlements should be added based on the Joiner process and the mapping rules in the roles.

There is no problem with steps 1 and 3, but I don’t know how to remove all of the user’s permissions.  
I’ve tried the following code, based on the snippet from the Compass community, and there are no errors, it just does nothing

```java
Identity identity = context.getObjectByName(Identity.class, identityName);

List links = identity.getLinks();
for (Link link : links)
{
	String idName=link.getNativeIdentity();
	String appname=link.getApplicationName();
	ProvisioningPlan plan = new ProvisioningPlan();
	plan.setIdentity(identity);
	plan.setNativeIdentity(idName); 

	AccountRequest accountRequest = new AccountRequest(); 
	accountRequest.setApplication(appname); 
	accountRequest.setOperation(AccountRequest.Operation.Modify);

	Filter filter1 = Filter.eq("application.name",appname); 
	Filter filter2 = Filter.eq("identity.name", idName); 
	Filter filter = Filter.and(filter1, filter2); 
	QueryOptions qo = new QueryOptions(); 
	qo.addFilter(filter); 
	Iterator it = context.search(IdentityEntitlement.class, qo); 

	if (it.hasNext()) { 
		while (it.hasNext()) { 
			IdentityEntitlement idEntitlement = it.next(); 
			if (accountRequest.getNativeIdentity() == null) {  
			}
			accountRequest.add(new AttributeRequest(idEntitlement.getName(), ProvisioningPlan.Operation.Remove, idEntitlement.getValue())); 
		}
	}

	plan.add(accountRequest);

	String assigner="spadmin";
	// Fire off the plan to the Provisioner to execute: 
	Provisioner provisioner = new Provisioner(context); 
	provisioner.setAssigner(idName); // String of Identity making the change. 
	provisioner.compile(plan); 
	provisioner.execute();
}

```

So if anyone has had the same problem, or knows how to deal with it, I’d love to hear from you.

Thanks,  
Danylo

---

<div class="post-metadata">

**Author:** ![Arun-Kumar](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/arun-kumar/32/15128_2.png) [@Arun-Kumar](https://developer.sailpoint.com/discuss/u/Arun-Kumar)\
**Post date:** [December 10, 2024, 3:39pm UTC](https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927/2 "2024-12-10T15:39:17Z")

</div>

Hi @d_pustovoitov ,

When roles are removed, the associated entitlements are also removed from the user. However, if the “Retain assigned entitlements when roles are removed” option is enabled, the entitlements will not be removed.  
Please check this option. Gear Icon —\> Global Settings —\> IdentityIQ Settings —\> Roles tab.

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/8/9/891771f8115444e418fbf7e1e84f0511ff9f059c.png)

Additionally, the nativeIdentity should be set on the accountRequest in the rule.

```auto
	plan.setIdentity(identity);
	 
        AccountRequest accountRequest = new AccountRequest(); 
	accountRequest.setApplication(appname); 
	accountRequest.setOperation(AccountRequest.Operation.Modify);
       accountRequest.setNativeIdentity(idName);

```

---

<div class="post-metadata">

**Author:** ![d\_pustovoitov](https://avatars.discourse-cdn.com/v4/letter/d/46a35a/32.png) [@d\_pustovoitov](https://developer.sailpoint.com/discuss/u/d_pustovoitov)\
**Post date:** [December 10, 2024, 3:47pm UTC](https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927/3 "2024-12-10T15:47:02Z")

</div>

Hi @Arun-Kumar ,

Thank you for your reply.

This option is enabled and all the entitlements that are associated with the assigned roles are removed on the 1st step. The problem is that on the 2nd step we want to remove all of the detected roles and as I’ve read on the community dicussions the only way to remove them is to revoke the entitlement.

I’ll try to add the native identity to the account request, thanks.

---

<div class="post-metadata">

**Author:** ![Felix\_Witt](https://avatars.discourse-cdn.com/v4/letter/f/7ab992/32.png) [@Felix\_Witt](https://developer.sailpoint.com/discuss/u/Felix_Witt)\
**Post date:** [December 10, 2024, 4:03pm UTC](https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927/4 "2024-12-10T16:03:46Z")

</div>

> [@d\_pustovoitov](#):
>
> `plan`

Native Identity is definitely required. You could try to have the provisioning plan logged and post it here.

---

<div class="post-metadata">

**Author:** ![d\_pustovoitov](https://avatars.discourse-cdn.com/v4/letter/d/46a35a/32.png) [@d\_pustovoitov](https://developer.sailpoint.com/discuss/u/d_pustovoitov)\
**Post date:** [December 11, 2024, 1:20pm UTC](https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927/5 "2024-12-11T13:20:02Z")

</div>

Hi @Felix_Witt ,

Thanks for your reply.

I added the `accountRequest.setNativeIdentity(idName);` as Arun suggested, but it didn’t help.  
I’ve also added the `plan.toXml()` for logging. But after the "Provisioning Plan XML: " there is not much I can understand. As I see there are 4 different plans for some of the connected applications.  
I’ve changed some of the data to “\*\*\*\*\*” and some of it is corrupted because of using the cyrrylic symbols.

Thanks.

[plans.xml](https://developer.sailpoint.com/discuss/uploads/short-url/zMLFPh9miqJLWVd7iYF5uqbANp9.xml) (44.5 КБ)

---

<div class="post-metadata">

**Author:** ![Arpitha1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/arpitha1/32/20512_2.png) [@Arpitha1](https://developer.sailpoint.com/discuss/u/Arpitha1)\
**Post date:** [December 12, 2024, 2:44am UTC](https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927/6 "2024-12-12T02:44:55Z")

</div>

Hi @d_pustovoitov

I noticed that the ‘attribute requests’ are not present inside the account requests. Could you please confirm if the iteration is occurring and whether the outgoing plan includes the attribute request? Perhaps you can add loggers inside while loop and check.

---

<div class="post-metadata">

**Author:** ![d\_pustovoitov](https://avatars.discourse-cdn.com/v4/letter/d/46a35a/32.png) [@d\_pustovoitov](https://developer.sailpoint.com/discuss/u/d_pustovoitov)\
**Post date:** [December 12, 2024, 8:48am UTC](https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927/7 "2024-12-12T08:48:36Z")

</div>

Hi @Arpitha1 ,

Yes, you’re right. I’ve added the next lines to code:

```auto
	if (it.hasNext()) { 
		while (it.hasNext()) { 
			IdentityEntitlement idEntitlement = it.next(); 
			log.info("IdentityEntitlement Name: " + idEntitlement.getName());

```

And there is no log entries for the Entitlement Name. So the while loop is not working. Probably there is a problem with the filter attributes…

Thanks.

---

<div class="post-metadata">

**Author:** ![Arun-Kumar](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/arun-kumar/32/15128_2.png) [@Arun-Kumar](https://developer.sailpoint.com/discuss/u/Arun-Kumar)\
**Post date:** [December 12, 2024, 8:52am UTC](https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927/8 "2024-12-12T08:52:19Z")

</div>

Hi @d_pustovoitov ,

identity.name should be identityName not a nativeIdentity.Try with below filter.

```auto

	Filter filter1 = Filter.eq("application.name",appname); 
	Filter filter2 = Filter.eq("identity.name", identity.getName());

```

---

<div class="post-metadata">

**Author:** ![Arpitha1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/arpitha1/32/20512_2.png) [@Arpitha1](https://developer.sailpoint.com/discuss/u/Arpitha1)\
**Post date:** [December 12, 2024, 9:07am UTC](https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927/9 "2024-12-12T09:07:11Z")

</div>

@d_pustovoitov As arun suggested, If idName represents account’s native identity then update the filter as below.

Filter filter2 = Filter.eq(“identity.name”, identityName);

Also, comment below line  
plan.setNativeIdentity(idName);

native identity is required on account request, I see, that you kept it in code already.

---

<div class="post-metadata">

**Author:** ![d\_pustovoitov](https://avatars.discourse-cdn.com/v4/letter/d/46a35a/32.png) [@d\_pustovoitov](https://developer.sailpoint.com/discuss/u/d_pustovoitov)\
**Post date:** [December 12, 2024, 9:29am UTC](https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927/10 "2024-12-12T09:29:45Z")

</div>

Hi @Arun-Kumar ,

Yes, I’ve changed the filter and the rule works now.

Thank you all for your help!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [February 10, 2025, 9:30am UTC](https://developer.sailpoint.com/discuss/t/removing-all-users-roles-and-entitlements/92927/11 "2025-02-10T09:30:10Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
