Application entitlement (AD group) inherited by all AD Accounts

Hello,

In our environment we have multiple applications with application entitlements which are AD groups. 

We have one primary user identity. Users are able to request through web portal additional AD account but each from different domain, not from the same.

When user has multiple AD account assigned and when request application entitlement the entitlement is assigned to all (inherited) AD accounts.

example

Identity has AD account XX and AD account ZZ

We have application entitlement which is ad group from AD domain XX

User identity get assigned this application entitlement and it is inherited by AD account XX but also by AD account ZZ.

Is it possible to anyhow control that only correct AD account will get the entitlement?

Thank you!