In the documentation for the Identity Store schema it is written: "Setting an entry to inactive has the same effect as deleting it, i.e. the attribute triggers the deprovisioning task for all target systems of the identity. Depending on the type of a specific target system, the de-provisioning task deletes or locks the user account."
When looking into the deprovisioning tasks in the SAP provisioning framework it however looks like accounts are deleted both in the ABAP and in the Java deprovisioning task.
I would have expected a standard implementation of an ABAP deprovisioning task to do the following:
-Set the users user group to INACTIVE
-Set validity date to expired
-Remove roles associated with the user
-Lock the user
I don't particularly like deleting user accounts in target systems. Do I have to write my own deprovisining task to address this issue?