I have an AD driver (#1) that grants or revokes a user account on an AD
server based on entitlements. I have another driver (#2) that needs to
check the status of the entitlement on driver (#1). How the driver (#2)
operates depends on what the entitlement status is - Granted or

What I have seen from policy_dtd, you can only make request for named
entitlement in the current operation - token-removed-entitlement,
token-added-entitlement and do-implement-entitlement, which means that
#2 can not make request for entitlement that is attached to driver

I am thinking of checking DirXML-EntitlementResult for a status change
for a specific user, but I'm not sure if this is the right approach.

Best regards

data_dong's Profile: https://forums.netiq.com/member.php?userid=6770
View this thread: https://forums.netiq.com/showthread.php?t=54281