Sorry if this comes out wrong, but I come from an application background and wanted to know how:
A user can be assigned an Active Directory role and place an Expiry date to their access to that role without removing the role from their access.
The reason is, that a user can act in their managers position while the manager is on leave and I would like to assign the user the role of their manager and set an expiry date to the role. For auditing purposes, I can always see what roles that user has had and when they had access to that role and I don’t have to remember to remove it when the citation changes.
I can do this in many software applications, but can not see how I can do this in Active directory.