Hi,
I have an AD driver (#1) that grants or revokes a user account on an AD
server based on entitlements. I have another driver (#2) that needs to
check the status of the entitlement on driver (#1). How the driver (#2)
operates depends on what the entitlement status is - Granted or
revoked.

What I have seen from policy_dtd, you can only make request for named
entitlement in the current operation - token-removed-entitlement,
token-added-entitlement and do-implement-entitlement, which means that
#2 can not make request for entitlement that is attached to driver
(#1).

I am thinking of checking DirXML-EntitlementResult for a status change
for a specific user, but I'm not sure if this is the right approach.

Best regards
Thanh


--
data_dong
------------------------------------------------------------------------
data_dong's Profile: https://forums.netiq.com/member.php?userid=6770
View this thread: https://forums.netiq.com/showthread.php?t=54281