I am running OIM 10G with the AD connector but the default behavior is to remove users once they no longer have any entitlements. I was wondering if there is a way to only disable users once all the entitlements are removed rather than revoking the user. Any help you can give would be appreciated.
My initial idea would be to change the Process Definition of the AD Connector "Delete User" task to use the Adapter Task from your "Disable User" task. Also, I would change the "Task to Object Status Mapping" to "Disabled" for a "C" status.