Account Access entitlement
When granted during the Grant step of Enforcement, enables a target user account. The user can now log in to the account.
Typically paired with the Account entitlement, but is a separate entitlement so you can issue disabled accounts prior to a user's start date, and only activate the account when the user is onboarded.
When revoked during the Revoke step, disables a target user account. The user can no longer log into the account.
Tip
To give users immediate access to new accounts, assign the Account and Account Access entitlements together, in a single business rule.