Hi,
There are a couple of options, which allow to update the user profile in the cloud directory before triggering a provisioning on Active Directory
You could configure AppRoles (AppRole mgmt) where you assign permissions (AD account) and cloud group(s)/roles to the AppRole. Once you have modified the user with the values , add the user to a specific group (part of the appRole) and the AD account will be provisioned
Another option is to use Dynamic groups which you also can use with the AppRole. The Dynamic group feature works on user attributes (or condition set )
https://www.ibm.com/docs/en/security-verify?topic=verify-requestable-features (Dynamic groups (Beta CI-46644))
This should allow to first update the user profile before the provisioning is scheduled.
Hope this helps
Regards
Serge Vereecke
------------------------------
Serge Vereecke
------------------------------