I have an identity policy that, in some situations, removes a user from a provisioning role. I need the system to apply the same behaviour as when synchronizing a user and flagging "Remove extra accounts". Is that possible?
When the Identity Policy removes the provisioning role from the user that same request should contain eTSyncDelete=1. The IM Server should already be doing this. Be sure you are on the latest product maintenance for your version. If the problem still persists after that then you should open a support case.