# When removing a role, after executing update provisioning policy, sailpont is unable to proceed to process before provisioning rule and Remove Entilement before operation rule

**URL:** <https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416>\
**Category:** IIQ Discussion and Questions\
**Tags:** identityiq, provisioning\
**Created:** [September 22, 2024, 3:52pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416 "2024-09-22T15:52:56Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![norman\_mercader](https://avatars.discourse-cdn.com/v4/letter/n/4bbf92/32.png) [@norman\_mercader](https://developer.sailpoint.com/discuss/u/norman_mercader)\
**Post date:** [September 22, 2024, 3:52pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416/1 "2024-09-22T15:52:56Z")

</div>

Hi, I am currently working on a webservice connector in SailPoint IIQ 8.3, I am encountering an issue wherein, when removing a role, after executing the update provisioning policy rule, it does not proceed to process the before provisioning rule and remove entitlement before operation rule.

---

<div class="post-metadata">

**Author:** ![enistriminsait](https://avatars.discourse-cdn.com/v4/letter/e/58f4c7/32.png) [@enistriminsait](https://developer.sailpoint.com/discuss/u/enistriminsait)\
**Post date:** [September 22, 2024, 4:00pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416/2 "2024-09-22T16:00:55Z")

</div>

Hi @norman_mercader,

sorry, I am little confuse.

> [@norman\_mercader](#):
>
> after executing the update provisioning policy rule

where and how are you executing this rule?

> [@norman\_mercader](#):
>
> remove entitlement before operation rule.

Can you explain better?

Ps If you can share the code or some screenshoot

---

<div class="post-metadata">

**Author:** ![norman\_mercader](https://avatars.discourse-cdn.com/v4/letter/n/4bbf92/32.png) [@norman\_mercader](https://developer.sailpoint.com/discuss/u/norman_mercader)\
**Post date:** [September 22, 2024, 4:37pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416/4 "2024-09-22T16:37:40Z")

</div>

The expected process is; when removing a role from existing user, the first process is to execute the update provisioning policy rule, in the said rule there is an attribute named isConcurrent with boolean value that will be updated to true/false base on type of entitlements/group present in the role that is going to be removed, Then it should generate a plan that has the updated value for isConcurrent. Then in before provisioning rule, it will check the value of isConcurrent, If it is true, I have to add another attribute request to the plan and assign specific value to the attribute request. then it should proceed with the removal of entitlements/group. but what what happened was it only process the update provisioning policy rule and stopped.

By the way, in adding of role to existing user, it go through the same process before adding of entitlement/groups but it was successful.

---

<div class="post-metadata">

**Author:** ![enistriminsait](https://avatars.discourse-cdn.com/v4/letter/e/58f4c7/32.png) [@enistriminsait](https://developer.sailpoint.com/discuss/u/enistriminsait)\
**Post date:** [September 22, 2024, 4:46pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416/5 "2024-09-22T16:46:17Z")

</div>

Ok, maybe I understand 😅 🤞

like I would do:

On webservice:

- Operations: getObject & Update Account configured

First Rule → Build the plan setting Modify like operation  
Before Rule → Control and add(or not) the attribute in according to logic  
Before Operation Rule → change the body to send

Its very import to have the getObject because after each change, SP launch an getObject to update th object on SP. If you dont have it, you need to make an aggregation.

Do you have the getObject op?

So, if the remove doesnt work could be for some reasons.

- Plan: check the operation and the attributes(but I think in your case its correct)
- Operation: check if you launch the correct operation
- Body: check if the body have all the property that you want and it accepted by the webservice

Also, review the logs, write new on your rules and check every step and active the webservice logs([log4j guide](https://community.sailpoint.com/t5/Working-With-Support-Knowledge/Log4j-Support-Guide/ta-p/137421)):  
`log4j.logger.openconnector.connector.webservices.WebServicesConnector=debug (or trace)`

---

<div class="post-metadata">

**Author:** ![norman\_mercader](https://avatars.discourse-cdn.com/v4/letter/n/4bbf92/32.png) [@norman\_mercader](https://developer.sailpoint.com/discuss/u/norman_mercader)\
**Post date:** [September 22, 2024, 4:52pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416/6 "2024-09-22T16:52:50Z")

</div>

these are the operation that I have configured:

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/b/8/b821c855812d69db80396a753d50b3e0c84c1355.png)

---

<div class="post-metadata">

**Author:** ![norman\_mercader](https://avatars.discourse-cdn.com/v4/letter/n/4bbf92/32.png) [@norman\_mercader](https://developer.sailpoint.com/discuss/u/norman_mercader)\
**Post date:** [September 22, 2024, 4:58pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416/7 "2024-09-22T16:58:06Z")

</div>

By the way, my code for removal of entitlements was already tested and working, I just encountered this issue last week.

---

<div class="post-metadata">

**Author:** ![enistriminsait](https://avatars.discourse-cdn.com/v4/letter/e/58f4c7/32.png) [@enistriminsait](https://developer.sailpoint.com/discuss/u/enistriminsait)\
**Post date:** [September 22, 2024, 5:09pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416/8 "2024-09-22T17:09:19Z")

</div>

can you share how you build the plan and the rule?

---

<div class="post-metadata">

**Author:** ![norman\_mercader](https://avatars.discourse-cdn.com/v4/letter/n/4bbf92/32.png) [@norman\_mercader](https://developer.sailpoint.com/discuss/u/norman_mercader)\
**Post date:** [September 22, 2024, 5:44pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416/10 "2024-09-22T17:44:49Z")

</div>

Actually, I just build the rule from update provisioning policy

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/0/d/0d059f1eb3655986eb9a2e9f0012d6c87e88f06b.png)

during the time that the execution was successful, after executing update provisioning policy rule it dump the application then proceed with the execution of before provisioning rule and remove entitlements before operation rule.

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/f/5/f530d9b2372fa7020eb02cbc4a8eb3562fdd7bf0.png)

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/3/a/3ae72a7092570b9f76454dc8fa5e929c729b652c.png)

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/a/1/a16377f070e3a41e43fb892c8ae17cb0a429322f.png)

but, during the time that it failed it did not dump the application and did not proceed with the execution of before provisioning rule and remove entitlements before operation rule

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/a/0/a0f2157992b370c1ef36c057344f94f8a475b593.png)

---

<div class="post-metadata">

**Author:** ![enistriminsait](https://avatars.discourse-cdn.com/v4/letter/e/58f4c7/32.png) [@enistriminsait](https://developer.sailpoint.com/discuss/u/enistriminsait)\
**Post date:** [September 22, 2024, 6:11pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416/11 "2024-09-22T18:11:57Z")

</div>

without look the code is little hard.

But there:

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/a/1/a1ae2466353f00a84b3ba9c89cf52a051ee147fc.png)  
the request remove a groups and add a role, its correct?  
Is it by any chance that this role assigns the group you are deleting?

---

<div class="post-metadata">

**Author:** ![norman\_mercader](https://avatars.discourse-cdn.com/v4/letter/n/4bbf92/32.png) [@norman\_mercader](https://developer.sailpoint.com/discuss/u/norman_mercader)\
**Post date:** [September 22, 2024, 7:55pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416/14 "2024-09-22T19:55:26Z")

</div>

The user was assigned with 2 roles, role1 have this 2 groups or entitlements

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/6/c/6c9ae8f1f5560a151202eca235bd22b303834bc4.png)

and role2 has this group or entitlement

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/0/1/015f1b30be672513891707550228ff4f37b8bc5d.png)  
and I tried to create a request to remove role2.  
 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/5/e/5e8b6dc6359c22f83ae88946aeddd93c1de6f943.png)

the groups with CONC in the group name is considered concurrent group and the one that doesn’t have CONC is non concurrent. the requirement in the application, if the assigned groups are all concurrent, we assigned a value true to isconcurrent attribute and assign specific value to the roles attribute, if the value of isconcurrent is false we do not assign value to roles attribute. in the example on the screenshot, I tried to remove the non concurrent group so the remaining assigned groups are concurrent groups. that is why in the plan you can see that the roles attribute has the op value of add.

The main issue is; after executing the isconcurrent update provisioning policy rule, it did not trigger the before provisioning rule and remove entitlement before operation rule, that is why the removal was failed.

For additional information, I tried to request the role removal via batch request but the batch request also failed to execute because of this error

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/8/8/881d361d2e9269ff7c69a528bd92a82eae0c2cc5.png)  
and upon tracing the error message, I found out that the log error is coming from the code of workflow object  
 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/0/e/0eded386a4bd64dbc32c2a70605f7a21f22b041a.png)

---

<div class="post-metadata">

**Author:** ![enistriminsait](https://avatars.discourse-cdn.com/v4/letter/e/58f4c7/32.png) [@enistriminsait](https://developer.sailpoint.com/discuss/u/enistriminsait)\
**Post date:** [September 22, 2024, 10:01pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416/15 "2024-09-22T22:01:29Z")

</div>

can you share the rule?

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [November 21, 2024, 10:02pm UTC](https://developer.sailpoint.com/discuss/t/when-removing-a-role-after-executing-update-provisioning-policy-sailpont-is-unable-to-proceed-to-process-before-provisioning-rule-and-remove-entilement-before-operation-rule/82416/16 "2024-11-21T22:02:12Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
