# User Case - Active Directory Disabled

**URL:** <https://developer.sailpoint.com/discuss/t/user-case-active-directory-disabled/125799>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, identity-security-cloud\
**Created:** [May 7, 2025, 4:41pm UTC](https://developer.sailpoint.com/discuss/t/user-case-active-directory-disabled/125799 "2025-05-07T16:41:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![singlde](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@singlde](https://developer.sailpoint.com/discuss/u/singlde)\
**Post date:** [May 7, 2025, 4:41pm UTC](https://developer.sailpoint.com/discuss/t/user-case-active-directory-disabled/125799/1 "2025-05-07T16:41:49Z")

</div>

Hello everyone - This is not exactly related to Active Directory, but I having this issue for Active Directory so mentioned specifically for AD.  
When lifecycle state changed to Inactive - ISC is diabling the AD account and moving user to specific OU and removing all groups. all well till here.  
Now AD account is disabled directly on source, and now next day user lifecycle state is changed to inactive - in this case ISC is not touching the User’s AD account as in ISC User’s AD account is already disabled. Is there any way we execute the beforeprovisioning rule to move the user to specific OU and remove groups?

---

<div class="post-metadata">

**Author:** ![gourab](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/gourab/32/18650_2.png) [@gourab](https://developer.sailpoint.com/discuss/u/gourab)\
**Post date:** [May 7, 2025, 4:48pm UTC](https://developer.sailpoint.com/discuss/t/user-case-active-directory-disabled/125799/2 "2025-05-07T16:48:16Z")

</div>

> [@singlde](#):
>
> reprovisioning rule to move the user to specific OU and remove groups?

configure sync for the LCS value with an Active Directory attribute. In the event of a termination, this value will be updated in Active Directory, triggering a modification operation and executing the beforeprovisioning rule.

---

<div class="post-metadata">

**Author:** ![UjjwalJain](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/ujjwaljain/32/24704_2.png) [@UjjwalJain](https://developer.sailpoint.com/discuss/u/UjjwalJain)\
**Post date:** [May 7, 2025, 6:36pm UTC](https://developer.sailpoint.com/discuss/t/user-case-active-directory-disabled/125799/3 "2025-05-07T18:36:44Z")

</div>

Hi @singlde,

Do you have any birthright roles that are revoked when a user moves to an inactive LCS, or any workflow in place to remove roles under that condition? If so, that action will automatically trigger the _Before Provisioning_ rule, where you can handle it based on specific conditions.

Let me know if you’d like further clarification.

Thanks,  
Ujjwal

---

<div class="post-metadata">

**Author:** ![ganesh-atikes](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/ganesh-atikes/32/30093_2.png) [@ganesh-atikes](https://developer.sailpoint.com/discuss/u/ganesh-atikes)\
**Post date:** [May 7, 2025, 7:09pm UTC](https://developer.sailpoint.com/discuss/t/user-case-active-directory-disabled/125799/4 "2025-05-07T19:09:36Z")

</div>

I’m a bit unclear about one part — as you mentioned, when the lifecycle state (LCS) changes to ‘Inactive’, the account is already being disabled, moved to the specific OU, and group memberships are removed. Could you clarify why you’re asking specifically about moving the account and removing access again? If you could share more details about your use case or the scenario you’re trying to handle, I’d be happy to help further.

---

<div class="post-metadata">

**Author:** ![vishal\_kejriwal1](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/vishal_kejriwal1/32/10904_2.png) [@vishal\_kejriwal1](https://developer.sailpoint.com/discuss/u/vishal_kejriwal1)\
**Post date:** [May 7, 2025, 7:22pm UTC](https://developer.sailpoint.com/discuss/t/user-case-active-directory-disabled/125799/5 "2025-05-07T19:22:35Z")

</div>

> [@singlde](#):
>
> inactive - in this case ISC is not touching the User’s AD account as in ISC User’s AD account is already disabled

How you are making changes to user ( example disable , move and remove all groups ) using standard before provisiong rule ?

---

<div class="post-metadata">

**Author:** ![dgandhi](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/dgandhi/32/28686_2.png) [@dgandhi](https://developer.sailpoint.com/discuss/u/dgandhi)\
**Post date:** [May 7, 2025, 7:58pm UTC](https://developer.sailpoint.com/discuss/t/user-case-active-directory-disabled/125799/6 "2025-05-07T19:58:41Z")

</div>

Do you mean to say Before Provisioning rule will be triggered even if access gets removed because of assignment criteria of role not matching?

---

<div class="post-metadata">

**Author:** ![UjjwalJain](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/ujjwaljain/32/24704_2.png) [@UjjwalJain](https://developer.sailpoint.com/discuss/u/UjjwalJain)\
**Post date:** [May 8, 2025, 7:09am UTC](https://developer.sailpoint.com/discuss/t/user-case-active-directory-disabled/125799/8 "2025-05-08T07:09:46Z")

</div>

Yes, since the criteria are no longer satisfied, those entitlements will be revoked, and that will, in turn, trigger provisioning.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [July 7, 2025, 7:10am UTC](https://developer.sailpoint.com/discuss/t/user-case-active-directory-disabled/125799/9 "2025-07-07T07:10:24Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
