# Services Standard Before Provisioning Rule Not Triggering for Azure AD

**URL:** <https://developer.sailpoint.com/discuss/t/services-standard-before-provisioning-rule-not-triggering-for-azure-ad/55064>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, identity-security-cloud\
**Created:** [May 1, 2024, 4:54pm UTC](https://developer.sailpoint.com/discuss/t/services-standard-before-provisioning-rule-not-triggering-for-azure-ad/55064 "2024-05-01T16:54:35Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![edkmak](https://avatars.discourse-cdn.com/v4/letter/e/439d5e/32.png) [@edkmak](https://developer.sailpoint.com/discuss/u/edkmak)\
**Post date:** [May 1, 2024, 4:54pm UTC](https://developer.sailpoint.com/discuss/t/services-standard-before-provisioning-rule-not-triggering-for-azure-ad/55064/1 "2024-05-01T16:54:35Z")

</div>

Hi, I’m running into an issue where my Services Standard Before Provisioning Rule is not executing. Below is the rule:

```
"op": "add",
"path": "/connectorAttributes/cloudServicesIDNSetup",
"value": {
    "eventConfigurations": [
            {
                "eventActions": [
                    {
                        "Action":"ChangeOperation",
                        "Attribute": null,
                        "Value":"Enable"
                    },
                    {
                        "Action": "RemoveEntitlements",
                        "Attribute": "groups",
                        "Value": null
                    },
                    {
                        "Action": "RemoveEntitlements",
                        "Attribute": "servicePrincipals",
                        "Value": null
                    }
                ],
                "Identity Attribute Triggers": [
                    {
                        "Attribute": "cloudLifecycleState",
                        "Value": "recentInactive",
                        "Operation": "eq"
                    }
                ],
                "Operation": "Disable"
            }
        ]
    }

```

The rule seems to not be recognized by IDN as the ChangeOperation is ignored and no entitlements are even requested to be removed from the user’s account in Azure AD. Azure AD is configured to be disabled upon entering the recentInactive lifecycle state within the id profile.  
Any ideas?

---

<div class="post-metadata">

**Author:** ![jesvin90](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jesvin90/32/5301_2.png) [@jesvin90](https://developer.sailpoint.com/discuss/u/jesvin90)\
**Post date:** [May 2, 2024, 3:47am UTC](https://developer.sailpoint.com/discuss/t/services-standard-before-provisioning-rule-not-triggering-for-azure-ad/55064/2 "2024-05-02T03:47:04Z")

</div>

Hi @edkmak,

Welcome to the community. Here are the steps that could help troubleshoot the issue:

1. Check if you have the before provisioning rule assigned to the source. You can make use of the Visual studio code [extension](https://marketplace.visualstudio.com/items?itemName=yannick-beot-sp.vscode-sailpoint-identitynow) and check the source to see if the values exist under the before provisioning. If not, add them as below :

![image](https://global.discourse-cdn.com/sailpoint/original/2X/d/d4ff1b45ff505c58effb1a42f9d36eea954e0a80.png)

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/c/ce9f504928d4bd295f0f5b85d26e1e6cf7bdb4fb.png)

1. Make sure you see the event configurations under the source.

2. Click on the Disable button under the accounts section to see if the disable operation behavior and check the events/search to see the activities that are generated.

3. Remove the Identity trigger from the event config and check the behavior on clicking the disable button.

Let me know how it goes.

---

<div class="post-metadata">

**Author:** ![edkmak](https://avatars.discourse-cdn.com/v4/letter/e/439d5e/32.png) [@edkmak](https://developer.sailpoint.com/discuss/u/edkmak)\
**Post date:** [May 2, 2024, 4:10pm UTC](https://developer.sailpoint.com/discuss/t/services-standard-before-provisioning-rule-not-triggering-for-azure-ad/55064/3 "2024-05-02T16:10:25Z")

</div>

@jesvin90 I don’t see anything under the “beforeProvisioningRule” in the Azure AD source. However, I am unsure what values to populate into the “id” and “name” values. I thought the Services Standard Before Provisioning Rule is added to the source? I cannot find a id or name value available.

---

<div class="post-metadata">

**Author:** ![jesvin90](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jesvin90/32/5301_2.png) [@jesvin90](https://developer.sailpoint.com/discuss/u/jesvin90)\
**Post date:** [May 2, 2024, 4:36pm UTC](https://developer.sailpoint.com/discuss/t/services-standard-before-provisioning-rule-not-triggering-for-azure-ad/55064/4 "2024-05-02T16:36:01Z")

</div>

Hi @edkmak,

Have you uploaded the rule to the cloud.? If yes, do a GET call `https://{{tenant}}.api.{{domain}}.com/cc/api/rule/list` and you should be able to get the rule ID and name, which can then be added to your Azure source.

If the rule is not deployed yet, you can raise a SailPoint ticket to do that or make use of the SP-config. Take a look at the below thread which can be helpful.

> [@Services Standard Before Provisioning Rule](https://developer.sailpoint.com/discuss/t/services-standard-before-provisioning-rule/20623/3):
>
> @vijaylca Here’s the code from version 1.7.1 (available in the attached ZIP file in this article [https://community.sailpoint.com/t5/Working-With-Services-Knowledge/IdentityNow-Mock-Project/ta-p/208216](https://community.sailpoint.com/t5/Working-With-Services-Knowledge/IdentityNow-Mock-Project/ta-p/208216) import sailpoint.object.Application; import sailpoint.object.Attributes; import sailpoint.object.Filter; import sailpoint.object.Identity; import sailpoint.object.ManagedAttribute.Type; import sailpoint.object.ProvisioningPlan; import sailpoint.object.ProvisioningPlan.AccountRequest; imp…

---

<div class="post-metadata">

**Author:** ![KRM7](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/krm7/32/2685_2.png) [@KRM7](https://developer.sailpoint.com/discuss/u/KRM7)\
**Post date:** [May 2, 2024, 7:33pm UTC](https://developer.sailpoint.com/discuss/t/services-standard-before-provisioning-rule-not-triggering-for-azure-ad/55064/5 "2024-05-02T19:33:31Z")

</div>

ok, did you attach the Rule to your source ?

SailPoint will deploy the Rule in cloud but won’t patch to the source rite.

Thanks  
Krish

---

<div class="post-metadata">

**Author:** ![edkmak](https://avatars.discourse-cdn.com/v4/letter/e/439d5e/32.png) [@edkmak](https://developer.sailpoint.com/discuss/u/edkmak)\
**Post date:** [May 3, 2024, 2:09pm UTC](https://developer.sailpoint.com/discuss/t/services-standard-before-provisioning-rule-not-triggering-for-azure-ad/55064/6 "2024-05-03T14:09:37Z")

</div>

I have added the beforeProvisioningRule id and name to the Azure AD source and it seems to be picking it up now.

![image](https://global.discourse-cdn.com/sailpoint/original/2X/1/1044b4d0fb09ced61e8ca5a52e4d114a436c258d.png)

![image](https://global.discourse-cdn.com/sailpoint/original/2X/c/c21535dfe407f397cf9f9d5838545a0e377c44e2.png)

I am having trouble removing the entitlements but it seems that the rule is at least executing.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [July 2, 2024, 2:10pm UTC](https://developer.sailpoint.com/discuss/t/services-standard-before-provisioning-rule-not-triggering-for-azure-ad/55064/7 "2024-07-02T14:10:27Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
