Provisioning with accounts disabled

Hello everyone,

In this environment, I have a target system for both Active Directory and Azure AD connectors.

For AD, everything is managed with account definitions, and we create/delete/modify accounts.

However, for Azure AD, it’s different because we don’t have account definitions, and it’s managed via AD Connect, which synchronizes from AD, so we read directly from Azure.

The issue is that, after we read that the AAD account has been disabled, not all AAD groups are being removed (excluding those with group types of DynamicMembership, we don't need to remove that ones).

I’ve created a process to remove the assigned groups using process step handleComponents with the where clauses and in One Identity they are removed from the database, but the provisioning does not start because the account is disabled.

So, if the account is enabled, the provisioning starts successfully.

How can I resolve this issue?

Thank you,

Elena