# Removing Azure AD Entitlements using Services Standard Before provisioning rule

**URL:** <https://developer.sailpoint.com/discuss/t/removing-azure-ad-entitlements-using-services-standard-before-provisioning-rule/15726>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, identity-security-cloud, entitlements\
**Created:** [August 8, 2023, 7:10pm UTC](https://developer.sailpoint.com/discuss/t/removing-azure-ad-entitlements-using-services-standard-before-provisioning-rule/15726 "2023-08-08T19:10:52Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sachin\_Rajathadri](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sachin_rajathadri/32/6381_2.png) [@Sachin\_Rajathadri](https://developer.sailpoint.com/discuss/u/Sachin_Rajathadri)\
**Post date:** [August 8, 2023, 7:10pm UTC](https://developer.sailpoint.com/discuss/t/removing-azure-ad-entitlements-using-services-standard-before-provisioning-rule/15726/1 "2023-08-08T19:10:52Z")

</div>

Hello,

We are trying to remove the shared mailbox (Type: Entitlement) using Services Standard Before provisioning rule. We aggregated this as an entitlement from Azure AD source. So far, we have tried:

```auto
                       {
                            "Action": "RemoveEntitlements",
                            "Attribute": "Entitlement",
                            "Value": null
                        }

And,

                        {
                            "Action": "RemoveEntitlements",
                            "Attribute": "Entitlements",
                            "Value": null
                        }

And,

                        {
                            "Action": "RemoveEntitlements",
                            "Attribute": "groups",
                            "Value": null
                        },

```

We even noticed that this doesn’t come up in CCG logs (maybe because its an entitlement). We were able to remove this using certification but not using Before provisioning rule. Just FYI, we want to remove this entitlement upon LCS changes.  
Any help regarding this is much appreciated. Thanks!

---

<div class="post-metadata">

**Author:** ![iamnithesh](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/iamnithesh/32/4884_2.png) [@iamnithesh](https://developer.sailpoint.com/discuss/u/iamnithesh)\
**Post date:** [August 8, 2023, 7:16pm UTC](https://developer.sailpoint.com/discuss/t/removing-azure-ad-entitlements-using-services-standard-before-provisioning-rule/15726/2 "2023-08-08T19:16:00Z")

</div>

Can you please share the entire `eventConfiguration` json that you have added to the `cloudServicesIDNSetup`

---

<div class="post-metadata">

**Author:** ![Sachin\_Rajathadri](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sachin_rajathadri/32/6381_2.png) [@Sachin\_Rajathadri](https://developer.sailpoint.com/discuss/u/Sachin_Rajathadri)\
**Post date:** [August 8, 2023, 7:23pm UTC](https://developer.sailpoint.com/discuss/t/removing-azure-ad-entitlements-using-services-standard-before-provisioning-rule/15726/3 "2023-08-08T19:23:18Z")

</div>

Here it is,

```auto
                 "cloudServicesIDNSetup": {
            "eventConfigurations": [                
                {
                    "eventActions": [
                        {
                            "Action": "RemoveEntitlements",
                            "Attribute": "Entitlement",
                            "Value": null
                        },
                        {
                            "Action": "RemoveEntitlements",
                            "Attribute": "groups",
                            "Value": null
                        }
                    ],
                    "Identity Attribute Triggers": [
                        {
                            "Attribute": "cloudLifecycleState",
                            "Value": "inactive",
                            "Operation": "eq"
                        }
                    ],
                    "Operation": "Disable"
                }
            ]
        },

```

Just FYI, I have tried with both “Attribute”: “Entitlement” and “Attribute”: “groups” together and separately.

Thanks!

---

<div class="post-metadata">

**Author:** ![iamnithesh](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/iamnithesh/32/4884_2.png) [@iamnithesh](https://developer.sailpoint.com/discuss/u/iamnithesh)\
**Post date:** [August 8, 2023, 7:29pm UTC](https://developer.sailpoint.com/discuss/t/removing-azure-ad-entitlements-using-services-standard-before-provisioning-rule/15726/4 "2023-08-08T19:29:46Z")

</div>

Here is a screenshot from the READ ME file

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/8/88b8a16e4eed65395d462e2e3ba51ab9c636b89f.png)

Are `Entitlements` and `groups` the attribute names that you want to remove?

---

<div class="post-metadata">

**Author:** ![Sachin\_Rajathadri](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sachin_rajathadri/32/6381_2.png) [@Sachin\_Rajathadri](https://developer.sailpoint.com/discuss/u/Sachin_Rajathadri)\
**Post date:** [August 8, 2023, 7:35pm UTC](https://developer.sailpoint.com/discuss/t/removing-azure-ad-entitlements-using-services-standard-before-provisioning-rule/15726/5 "2023-08-08T19:35:12Z")

</div>

This makes sense. The attribute name is sharedMailbox, I will try this and let you know. Thanks!

---

<div class="post-metadata">

**Author:** ![iamnithesh](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/iamnithesh/32/4884_2.png) [@iamnithesh](https://developer.sailpoint.com/discuss/u/iamnithesh)\
**Post date:** [August 8, 2023, 7:36pm UTC](https://developer.sailpoint.com/discuss/t/removing-azure-ad-entitlements-using-services-standard-before-provisioning-rule/15726/6 "2023-08-08T19:36:46Z")

</div>

[SSI BeforeProvisioning Rule - README.pdf](https://developer.sailpoint.com/discuss/uploads/short-url/ws0whplUQDBBXInkf7ZZMQ23Mng.pdf) (110.2 KB)

File for your future reference 🙂

---

<div class="post-metadata">

**Author:** ![Sachin\_Rajathadri](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sachin_rajathadri/32/6381_2.png) [@Sachin\_Rajathadri](https://developer.sailpoint.com/discuss/u/Sachin_Rajathadri)\
**Post date:** [August 8, 2023, 7:42pm UTC](https://developer.sailpoint.com/discuss/t/removing-azure-ad-entitlements-using-services-standard-before-provisioning-rule/15726/7 "2023-08-08T19:42:57Z")

</div>

It worked, thanks for your help! 😊

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [October 7, 2023, 7:43pm UTC](https://developer.sailpoint.com/discuss/t/removing-azure-ad-entitlements-using-services-standard-before-provisioning-rule/15726/8 "2023-10-07T19:43:35Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
