Role revoke VS account entitlements

Hello All,

I’m looking for a spark that will help me with following task: our customer wants to know if it’s possible to implement in ISC following mechanism: when identity hit the ‘inactive’ life cycle state role is revoked but entitlements (on AD in particular) must remains untouched.

In normal situation entitlements will be obviously revoked (as they were assigned via role). Now, workflows might comes in handy but i can’t really put my finger on how it can work.

Any ideas are highly appreciated. Many thanks in advance

I can only think of modifying the provisioning plan by removing the entitlements from the plan, this can be done via Before Provisioning rule.

Hi @radoslaw_klimkowski ,

You can write before provisioning plan. In plan you will list of all access during the revocation for action so you can remove the roles from the plan and rest keep everything as it is. It will work without any issues.

FYR, find the attached link for B/F sample snippet Before Provisioning Rule | SailPoint Developer Community

IHTH :slightly_smiling_face: