# When inactive, remove entitlements or access profile

**URL:** <https://developer.sailpoint.com/discuss/t/when-inactive-remove-entitlements-or-access-profile/22437>\
**Category:** SHF Discussion and Questions\
**Tags:** workflows, identity-security-cloud, entitlements\
**Created:** [December 11, 2023, 6:41am UTC](https://developer.sailpoint.com/discuss/t/when-inactive-remove-entitlements-or-access-profile/22437 "2023-12-11T06:41:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sec\_tech](https://avatars.discourse-cdn.com/v4/letter/s/6f9a4e/32.png) [@sec\_tech](https://developer.sailpoint.com/discuss/u/sec_tech)\
**Post date:** [December 11, 2023, 6:41am UTC](https://developer.sailpoint.com/discuss/t/when-inactive-remove-entitlements-or-access-profile/22437/1 "2023-12-11T06:41:17Z")

</div>

> ‼ Please be sure you’ve read the [docs](https://developer.sailpoint.com/idn/docs/) and [API specs](https://developer.sailpoint.com/idn/api/getting-started) before asking for help. Also, please be sure you’ve [searched](https://developer.sailpoint.com/discuss/search?expanded=true) the forum for your answer before you create a new topic.

When an identity is marked as inactive or terminated,  
I would like to request the removal of entitlements access profiles granted upon authorization.

I’m currently in the workflow, so if there are any additional tasks required, please let me know so I can assist.

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/3/3bb6ba0c39c37a495b3642b52134548b27f8209b.png)  
 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/8/85bc18bd6846107e6d7a76e9fb760088e673b421.png)  
 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/5/5edbfc3f648b66d10aeb6bfc9910a23158bdf6e8.png)  
 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/1/160dd3299a5bf3b8cc68d0d377ce5832676c45f1.png)  
 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/3/3cb01301c7a0c6a14a6a53ecb22909cc6a4a8199.png)  
 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/3/38e7e911eb6dcb707f9fcf82b558cb5d4b250fb8.png)

Do I have to add HTTP Request to workflow?

If I have to add, how do I fill that information?

---

<div class="post-metadata">

**Author:** ![jsosa](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jsosa/32/31578_2.png) [@jsosa](https://developer.sailpoint.com/discuss/u/jsosa)\
**Post date:** [December 11, 2023, 12:54pm UTC](https://developer.sailpoint.com/discuss/t/when-inactive-remove-entitlements-or-access-profile/22437/2 "2023-12-11T12:54:43Z")

</div>

Hi @sec_tech ! I have this problem a couple of months ago, I could not get the Get Access/Manage Access work to achieve your objective, even putting the Manage Access inside a Loop.

I could do it with 2 HTTP Request actions, first one calls the IDN API to retrieve user’s entitlements, then put response in a Loop, and inside a the loop another HTTP Request which it calls IDN API to revoke entitlement.

I posted detailed solution here:

> [@Remove all entitlements with workflow](https://developer.sailpoint.com/discuss/t/remove-all-entitlements-with-workflow/16692/4):
>
> Hi Colin, sorry I forgot to return here. I was not able to get objective using the Get Access / Manage Access actions. Instead I replaced the Get Access with a HTTP action, calling the search api to find user entitlements, and then replaced Manage Access action with another HTTP action, this time removing each entitlement as a request. First HTTP Request JSON Body: { "indices": ["identities"], "query": { "query": "id:{…

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [February 9, 2024, 12:55pm UTC](https://developer.sailpoint.com/discuss/t/when-inactive-remove-entitlements-or-access-profile/22437/3 "2024-02-09T12:55:21Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
