# Removing Attribute Request from Cloud Before Provisioning Rule

**URL:** <https://developer.sailpoint.com/discuss/t/removing-attribute-request-from-cloud-before-provisioning-rule/206816>\
**Category:** SHF Discussion and Questions\
**Tags:** identity-security-cloud, rules, roles\
**Created:** [May 5, 2026, 1:20pm UTC](https://developer.sailpoint.com/discuss/t/removing-attribute-request-from-cloud-before-provisioning-rule/206816 "2026-05-05T13:20:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![vemadeepak](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vemadeepak/32/38053_2.png) [@vemadeepak](https://developer.sailpoint.com/discuss/u/vemadeepak)\
**Post date:** [May 5, 2026, 1:20pm UTC](https://developer.sailpoint.com/discuss/t/removing-attribute-request-from-cloud-before-provisioning-rule/206816/1 "2026-05-05T13:20:44Z")

</div>

Hello,

I have a requirement, if the Identity Attribute type is “ABC” then restrict the role assignment by provisioning/ deprovisioning roles.

I’m using using cloud based before provisioning rule to remove the attribute request from the plan so that role or access won’t be added or removed. Below is the reference code.

```auto
List accountRequests = plan.getAccountRequests();
  for( AccountRequest accountRequest: accountRequests ){
    if( accountRequest.getOperation().toString().equals("Modify") ){
      log.error("Modify Operation Started" );
      if (accountRequest.getAttributeRequests() != null) {  
        AttributeRequest oGAttrReq = accountRequest.getAttributeRequest("orgGroup");
        if (type != null @and type.equalsIgnoreCase("ABC")) {
            accountRequest.remove(oGAttrReq);
            continue;
        }
      } 
    }
  }

```

Above logic is not working. When an Identity satisfies the role criteria. Please assist me if there is anything wrong here

---

<div class="post-metadata">

**Author:** ![punna0001](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/punna0001/32/42011_2.png) [@punna0001](https://developer.sailpoint.com/discuss/u/punna0001)\
**Post date:** [May 5, 2026, 2:15pm UTC](https://developer.sailpoint.com/discuss/t/removing-attribute-request-from-cloud-before-provisioning-rule/206816/2 "2026-05-05T14:15:18Z")

</div>

Hey Deepak, the issue here is that this is being handled too late in the flow.

A Before Provisioning rule edits the provisioning plan before it goes to the source, but it does not stop the identity from qualifying for the automated role. If the identity still meets the role criteria, ISC will keep treating that role as assigned and can regenerate the provisioning on the next identity processing run. So even if the rule removes the attribute request today, it may come back tomorrow.

The cleaner fix would be to add the exclusion condition directly to the role assignment criteria:

```auto
Identity Attribute: type Does Not Equal ABC

```

Then run Apply Changes or let identity processing recalculate. That is the right control point for blocking automated role assignment rather than trying to intercept it mid-provisioning. More on that [here](https://documentation.sailpoint.com/saas/help/provisioning/role_assignment.html).

That said, there are also a few issues in the rule itself worth fixing:

1. `identity` is not a direct context variable in a cloud Before Provisioning rule. You would need to pull it from the plan instead. ([ref](https://developer.sailpoint.com/docs/extensibility/rules/cloud-rules/before-provisioning-rule/))

2. `orgAttrReq` is declared but `oGAttrReq` is passed to `remove()`, looks like a typo there.

3. `orgAttrReq` should be null-checked before removing, since `orgGroup` may not be present in every plan that comes through.

If you still want to keep the rule as a last-mile guardrail alongside the criteria fix, something like this should work:

```auto
import sailpoint.object.Identity;
import sailpoint.object.ProvisioningPlan.AccountRequest;
import sailpoint.object.ProvisioningPlan.AttributeRequest;

Identity identity = plan.getIdentity();
String type = identity != null ? (String) identity.getAttribute("yourAttributeName") : null;

List accountRequests = plan.getAccountRequests();

if (accountRequests != null && "ABC".equalsIgnoreCase(type)) {
    for (AccountRequest accountRequest : accountRequests) {
        if (accountRequest != null &&
            accountRequest.getOperation() != null &&
            "Modify".equalsIgnoreCase(accountRequest.getOperation().toString())) {

            AttributeRequest orgAttrReq = accountRequest.getAttributeRequest("orgGroup");

            if (orgAttrReq != null) {
                accountRequest.remove(orgAttrReq);
            }
        }
    }
}

```

Replace `"yourAttributeName"` with the actual identity attribute name for your type field.

---

<div class="post-metadata">

**Author:** ![mandarsane](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/mandarsane/32/35650_2.png) [@mandarsane](https://developer.sailpoint.com/discuss/u/mandarsane)\
**Post date:** [May 5, 2026, 2:19pm UTC](https://developer.sailpoint.com/discuss/t/removing-attribute-request-from-cloud-before-provisioning-rule/206816/3 "2026-05-05T14:19:28Z")

</div>

Hi @vemadeepak ,

Is this applicable only for “Modify” account operation or Create operation also

Please make sure Attribute name is “orgGroup”.

Code is not checking null condition specifically for any attribute request “orgGroup”.

Code is trying to remove “oGAttrReq” but attribute request variable name is “orgAttrReq”

---

<div class="post-metadata">

**Author:** ![vemadeepak](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vemadeepak/32/38053_2.png) [@vemadeepak](https://developer.sailpoint.com/discuss/u/vemadeepak)\
**Post date:** [May 6, 2026, 11:03am UTC](https://developer.sailpoint.com/discuss/t/removing-attribute-request-from-cloud-before-provisioning-rule/206816/4 "2026-05-06T11:03:08Z")

</div>

thank you for your response, since this is just a reference code. I just made some changes to the original code before pasting it here.

And code is working as expected without having any issues. I was checking the results in a wrong way.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [July 5, 2026, 11:03am UTC](https://developer.sailpoint.com/discuss/t/removing-attribute-request-from-cloud-before-provisioning-rule/206816/5 "2026-07-05T11:03:11Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
