Thanks Rob, will do 



On Thu, Jun 13, 2019 at 1:45 PM, Rob Crittenden
<rcritten@redhat.com> wrote:
Eric Fredrickson via FreeIPA-users wrote:
> Hello,
>
> I was wondering if there was a way or if this is on the roadmap for future work.  I have a use case where I'd like to create a user account, but add a rule where OTP must be assigned to the account within a certain time period (e.g. 24 hours).  If not, the account is disabled.  This leaves the end user with the ability to create their OTP and not have to distribute any secret keys/screenshots of the QR code, while removing administrative burden of manually checking accounts if they have OTP enabled.

There is no sort of rule engine in IPA where you can conditionally
disable accounts. There are similar RFEs for disabling on conditions,
for example due to inactivity, https://fedorahosted.org/freeipa/ticket/4975

Might be worth filing a separate ticket with your use case and
mentioning it in the other ticket so a generic solution can be created.

rob