As Geoff points out in his articale,;

"... although you may require an Entitlement to get a new account,
often the horses are well out of the barn and even though you want to
use entitlements, you need to match existing users, even if they do not
have the entitlement since it is much better to control them going
forward than to leave them stranded."

So when you are implementing entitlements for the first time in a
driver, can you add the Role or Entitlment to a set of users that match
an LDAP Filter, as an example?

This would sure make coding drivers much better as to not have to deal
the "old" and the Entitlement based provisioning and de-provisioning


Thank You for your help!

Jim Willeke