Blog
Overig

Segregation of Duties (SoD): wat het is en hoe je het afdwingt
Wat is segregation of duties (functiescheiding)? Uitleg, voorbeelden en waarom het vaak misgaat. Plus hoe je SoD-conflicten automatisch tegenhoudt.
Marcel van Beek · 4 min read

How do you apply AGDLP in a hybrid Entra/AD environment? (And why you shouldn't want to anymore)
Short answer: preferably not. AGDLP (Accounts → Global groups → Domain Local groups → Permissions) is a concept from the era of manual management. The entire nesting construction exists for one reason: to allow a human to assign permissions with as few mouse clicks as possible. As soon as an agent assigns group memberships directly based on HR data, this reason disappears and only the complexity remains. Moreover, in a hybrid environment, this complexity actively works against you, because Entra ID completely ignores nesting for licences and app assignment. In this article, you can read how AGDLP works and why it was once smart, where it breaks down in a hybrid environment, and what the modern alternative looks like: direct memberships, managed by automation.
Marcel van Beek · 5 min read

How do I set up role-based access control (RBAC) and least privilege for a municipality?
Start with the roles in your HR system and map them to roles, not to individual permissions per person. Group each role with precisely the access required for the job, adhering to the principle of least privilege. Manage these roles centrally and let an orchestration layer automatically assign and revoke them. This keeps access predictable, limited and demonstrable.
Mike Fraanje · 4 min read

Wat betekent de Cyberbeveiligingswet (NIS2) voor het toegangsbeheer van gemeenten, provincies en waterschappen?
Gemeenten, provincies en waterschappen worden onder de Cyberbeveiligingswet automatisch aangewezen als essentiële entiteit, ongeacht hun omvang, en vallen daarmee onder proactief toezicht. Toegangsbeheer is een vast onderdeel van de zorgplicht: toegang moet beperkt, rolgebaseerd en aantoonbaar zijn. Geautomatiseerd accountbeheer met logging is de praktische manier om daaraan te voldoen.
Mike Fraanje · 4 min read

How do I automatically revoke all access for an employee upon offboarding?
Link the HR system to an orchestration layer above Microsoft Entra ID or Google Workspace. As soon as the end-of-employment date is registered in the HR system, this layer automatically revokes or suspends the account and all linked permissions at that exact moment. This prevents active accounts of departed employees and records every change in a log.
Marcel van Beek · 4 min read

Wat vraagt de Baseline Informatiebeveiliging Overheid op het gebied van toegangsbeheer voor medewerkers?
De Baseline Informatiebeveiliging Overheid vraagt dat toegang voor medewerkers gecontroleerd wordt verleend, beperkt blijft tot wat nodig is voor de functie, periodiek wordt beoordeeld en bij vertrek direct wordt ingetrokken. Kort gezegd: rolgebaseerde toegang, least privilege, logging en een sluitende levenscyclus van accounts. Door het personeelssysteem te koppelen aan de werkomgeving automatiseer je precies die eisen.
Marcel van Beek · 3 min read

Waarom wordt Identity en Access Management steeds belangrijker in het onderwijs, en wat automatiseer je het beste eerst?
Identity en Access Management wordt belangrijker omdat onderwijsinstellingen steeds meer systemen gebruiken, terwijl de digitale dreiging toeneemt en de eisen rond toegangsbeheer strenger worden. Het account van een medewerker is vaak de toegangsdeur tot gevoelige data, dus tijdige toekenning en intrekking van rechten zijn cruciaal. Begin met automatiseren waar het risico en de werklast het grootst zijn: het aanmaken, wijzigen en intrekken van medewerkersaccounts vanuit het personeelssysteem.
Marcel van Beek · 4 min read

Wat vraagt het toetsingskader van SURFaudit op het gebied van toegangsbeheer voor medewerkers, en hoe automatiseer je dat?
Het toetsingskader van SURFaudit verlangt dat een instelling toegang van medewerkers gestructureerd toekent, wijzigt en intrekt, en dat aantoonbaar kan maken. Toegangsrechten mogen niet ruimer zijn dan nodig en moeten worden aangepast of ingetrokken zodra het dienstverband verandert of eindigt. Om volwassenheidsniveau 3 te halen, moet dit proces gedocumenteerd, formeel en aantoonbaar zijn. Automatisering vanuit het personeelssysteem maakt precies dat mogelijk.
Marcel van Beek · 3 min read

Hoe houd ik accounts en toegang van medewerkers in de kinderopvang bij ondanks veel verloop en wisselende locaties?
Maak het personeelssysteem leidend en laat de accounts automatisch meebewegen. Begint, verandert of vertrekt een medewerker, dan past de toegang in de werkomgeving zich vanzelf aan. Zo blijven accounts kloppen ondanks veel verloop, invalkrachten en collega's die op meerdere locaties werken, en blijven er geen vergeten accounts achter.
Marcel van Beek · 3 min read

Hoeveel tijd ben je kwijt aan het handmatig regelen van accounts, en hoe houd je daar tijd aan over?
Het handmatig aanmaken, wijzigen en intrekken van accounts kost de ICT afdeling structureel veel tijd, juist op de drukste momenten van het jaar. Door het personeelssysteem leidend te maken en de accounts automatisch te laten meebewegen, verdwijnt het meeste van dat herhaalwerk. De winst zit niet alleen in tijd, maar ook in minder fouten en minder vergeten accounts.
Marcel van Beek · 3 min read

How do I automatically revoke accounts of departing employees?
Integrate your HR system with an orchestration layer that runs on top of Microsoft Entra ID or Google Workspace. As soon as an employee-status is set to inactive in the HR system, this layer disables the account, revokes access rights, and logs every step. This ensures offboarding occurs automatically on the correct date, without manual ICT department action required.
Marcel van Beek · 3 min read

De zelfevaluatie van het Normenkader IBP voorbereiden (vóór 2027)
Vanaf 1 januari 2027 moet elk schoolbestuur in het funderend onderwijs via een zelfevaluatie weten waar het staat ten opzichte van het Normenkader IBP, en een plan van aanpak hebben om volwassenheidsniveau 3 te bereiken. Toegangsbeheer is een van de domeinen die je daarbij beoordeelt. Door dat nu te automatiseren, ga je de zelfevaluatie in met een sterk uitgangspunt en met bewijs bij de hand.
Marcel van Beek · 4 min read

Volwassenheidsniveau 3 bereiken voor toegangsbeheer
Zowel het Normenkader IBP (funderend onderwijs) als het toetsingskader van SURFaudit (mbo en hoger onderwijs) hanteren volwassenheidsniveau 3 als streefniveau. Voor toegangsbeheer betekent niveau 3: het beleid is vastgelegd, de uitvoering is geautomatiseerd en consistent, en je kunt aantonen dat het werkt. Geautomatiseerde provisioning vanuit het personeelssysteem brengt je daar het snelst.
Marcel van Beek · 3 min read

Normenkader IBP of Cyberbeveiligingswet: wat is het verschil?
Het Normenkader IBP is de afgesproken norm voor digitale veiligheid in het funderend onderwijs (po en vo), met een zelfevaluatie vanaf 2027. De Cyberbeveiligingswet is echte wetgeving, de Nederlandse uitwerking van de Europese richtlijn NIS2, en geldt onder meer voor hbo en wo. Beide leggen veel nadruk op toegangsbeheer, maar ze verschillen in status, doelgroep en tijdlijn.
Marcel van Beek · 4 min read

Je personeelssysteem koppelen aan Microsoft 365 of Entra ID: AFAS, Visma of HR2day
In het onderwijs zijn AFAS, Visma (Visma.net HRM, de opvolger van Youforce) en HR2day de meest gebruikte personeels- en salarissystemen. Geen van deze maakt zelf accounts aan in Microsoft 365 of Google Workspace. Een orchestratielaag tussen je personeelssysteem en de werkomgeving vertaalt elke personeelsmutatie automatisch naar het juiste account met de juiste toegang.
Marcel van Beek · 4 min read

Onboarding en offboarding van medewerkers in het onderwijs automatiseren
In het onderwijs wisselt personeel continu, met veel invallers en mensen die op meerdere scholen werken. Wordt offboarding niet net zo zorgvuldig geautomatiseerd als onboarding, dan blijven accounts achter in Microsoft 365, het netwerk en losse applicaties. Door beide vanuit het personeelssysteem te automatiseren, met eerst uitschakelen en daarna opruimen, voorkom je achtergebleven accounts en voldoe je aantoonbaar aan de normen.
Marcel van Beek · 4 min read

Wat vraagt het Normenkader IBP op het gebied van toegangsbeheer?
Identity en Access Management is een van de 15 domeinen in het Normenkader Informatiebeveiliging en Privacy voor het Funderend Onderwijs (IBP). Concreet vraagt het kader om sterke authenticatie, toegang volgens least privilege, geautomatiseerd beheer van de levenscyclus van accounts en aantoonbare logging. Wie dat vanuit het personeelssysteem automatiseert, dekt deze normen in één keer af.
Marcel van Beek · 4 min read

VTS Transport zet met Joinly de eerste stap naar slimmer IAM

Joiner Mover Leaver (JML) uitgelegd
Joiner Mover Leaver (JML) beschrijft hoe organisaties onboarding, mutaties en offboarding automatiseren. Ontdek hoe HR-gedreven identity lifecycle management zorgt voor correcte toegang, minder beheer en betere security.
Morten Broers · 5 minutes

Welke Microsoft Entra logs heb je nodig voor NIS2 audits?
Ontdek welke Microsoft Entra logs je nodig hebt voor NIS2 audits en hoe je identity logging audit-proof inricht.
Marcel van Beek · 5 minutes

Microsoft Entra ID en NIS2: zo maak je je tenant compliant
Ontdek hoe je Microsoft Entra ID NIS2-proof inricht. Praktische stappen voor IAM governance, MFA, logging en lifecycle-automatisering.
Jeroen van Langenbroek · 8 minutes

Wat is NIS2 en wat betekent dit voor Identity & Access Management?
NIS2 verandert cybersecurity van best practice naar wettelijke verplichting. Maar wat betekent dat concreet voor Identity & Access Management? In dit artikel leggen we uit waarom IAM centraal staat binnen NIS2, welke eisen er gelden en hoe je Microsoft Entra ID en toegangsbeheer future-proof inricht.
Mike Fraanje · 7 minutes

Clean up Active Directory and Entra ID via Joinly
Many organisations struggle with sprawl of groups in Active Directory and Microsoft Entra ID. In this blog, you will read how Joinly provides insight, helps clean up, and makes access rights manageable.
Mike Fraanje · 10 min read

Ransomware and IAM – why identity security is your first line of defense
Dylan Klümann · 4 min read

MFA frustrations: How to deploy multi-factor authentication in a user-friendly and secure manner
Dylan Klümann · 6 min read

IAM as a basis for Zero Trust: How identity forms the heart of a Zero Trust architecture
Dylan Klümann · 6 min read

IAM and onboarding: How to give new employees full access on day one
Marcel van Beek · 5 min read

IAM as the foundation for security governance: why IAM is the strategic pillar
Security governance revolves around control, predictability, and the structural protection of information. However, many governance efforts falter when access management is manual or fragmented. IAM forms the foundation of modern security because it determines who has access to data, applications, and systems. Joinly makes IAM simple, flexible, and fully automated. By synchronizing identities from HR and combining access rules through RBAC and ABAC, a reliable and scalable governance model is created that structurally reduces risks.
Mike Fraanje · 7 min read

Balance between security and usability: Why IAM is the enabler every organisation needs
Nathan Snippe · 5 min read

RBAC vs. ABAC: why the combination works best
RBAC and ABAC are often seen as complex IAM models, leading organizations to believe they need to make a difficult strategic choice. Joinly breaks that thought. The platform simplifies IAM by flexibly using RBAC and ABAC together without technical complexity. HR provides identity data, Joinly automatically determines access according to policy. This results in a no-nonsense IAM solution that grows with the organization and always regulates access correctly.
Mike Fraanje · 6 min read

IAM and GDPR: how effective access management supports data privacy
The GDPR requires organisations to handle personal data carefully and ensure that only authorised individuals have access to data. Many data breaches occur because permissions are not revoked in time or because outsiders have overly broad access. IAM helps to structurally ensure data privacy. Joinly synchronises identities from the HR system and determines access based on RBAC and ABAC. This results in a controlled, logical, and auditable access process that perfectly aligns with the GDPR.
Mike Fraanje · 5 min read

Audits and access rights: how IAM prevents audits from becoming a nightmare
Many organizations find audits around access management to be time-consuming and stressful. Identities and permissions are spread across multiple systems, accounts are managed manually, and collecting evidence takes days. With IAM, a central and consistent access model is created where provisioning, deprovisioning, and logging occur automatically. Joinly synchronizes identities from the HR system, applies RBAC and ABAC, and offers a complete audit trail. This makes audit preparation simple and predictable.
Mike Fraanje · 6 min read

How IAM helps with certification and audits such as NIS2 and ISO27001
Mike Fraanje · 8 min read

Self-service IAM: Why modern organisations allow employees to request access themselves
Dylan Klümann · 5 min read

IAM and SaaS sprawl, how to maintain control over all cloud applications
SaaS sprawl occurs when teams increasingly use more cloud applications without central management, leading to increased risks, costs, and shadow IT. Joinly brings structure by automatically synchronising identities from the HR system, while access is centrally managed via RBAC and ABAC. This creates a secure, manageable cloud environment where onboarding, offboarding, and access management are fully automated — without additional work for HR or IT.
Mike Fraanje · 6 min read

Automatic deprovisioning: prevent former employees and externals from retaining access
Automatic deprovisioning prevents former employees, consultants, and suppliers from retaining access to systems. Discover how Joinly fully automates offboarding and prevents data leaks.
Mike Fraanje · 9 min read

Single Sign-On (SSO) in practice; more convenience and security for employees
Morten Broers · 5 min read

The danger of shared accounts, why this is truly unacceptable in 2025
Shared accounts may seem practical, but in 2025 they pose a serious risk to security, compliance, and business continuity. In this blog, Joinly explains why unique identities are indispensable and how modern Identity & Access Management helps organizations regain control and oversight.
Dylan Klümann · 5 min read

Cybercrime costs Dutch companies millions, why IAM is more important now than ever
Research by ABN AMRO and MWM2 shows that one in five companies suffered financial damage due to cyber attacks in 2024. In many cases, this is caused by account misuse, insufficient access management, or incorrect offboarding. By automating IAM, such as with Joinly, accounts, permissions, and access are centrally secured, and damage is prevented.
Mike Fraanje · 4 min read

AD vs. Entra ID: What is the role of Active Directory and when should you transition to Microsoft Entra ID?
Discover the difference between Active Directory and Microsoft Entra ID. Learn when to make the switch and how Joinly simplifies the transition with flexible provisioning.
Nathan Snippe · 6 min read

IAM and legacy systems, how to cleverly integrate older applications
Many organisations want to modernise IAM, but still use older or hard-to-integrate applications. With Joinly, you can securely and automatically integrate legacy systems into your Identity & Access Management processes. Thanks to flexible integrations, smart data mapping, and HR-driven provisioning, even outdated software becomes part of a future-proof and compliant IAM landscape without replacing systems.
Morten Broers · 10 min read

Shadow IT: the invisible risk of poor Identity & Access Management
Dylan Klümann · 10 min read

What is Identity and Access Management (IAM)-2?
Companies are digitising rapidly. HR-systems, SaaS-tools, customer portals, mobile apps – everyone works with accounts, logins, and permissions. But who actually keeps an overview of who has access to what? Exactly there, Identity & Access Management (IAM) comes into play.

The architecture of Joinly explained: how everything integrates
Joinly integrates HR systems, Microsoft Entra ID, and applications through a secure and scalable architecture. This article explains how it works, step by step and without technical jargon.
Marcel van Beek · 6 min read

Understanding SCIM: the backbone of modern IAM provisioning
What is SCIM and why is it so important for identity provisioning? In this blog, we explain how SCIM works, why more and more SaaS applications support it, and how platforms like Joinly use it to enable HR-driven IAM automation.
Morten Broers · 8 min read

HR as the new source of truth for Identity & Access Management
More and more organizations are shifting from IT-driven to HR-driven identity management. No longer does the helpdesk decide who gets access, but the HR system that records the lifecycle of each employee. In this article, you will learn why HR is the new source of truth for IAM.
Marcel van Beek · 7 min read

What is Identity and Access Management? (IAM)
Identity & Access Management (IAM) ensures that the right people have access to the right systems – securely, efficiently, and controlled. In this blog, you will read what IAM exactly is, why it is indispensable for modern organizations, and how solutions like Joinly IAM, Entra ID, and Active Directory work together to automate access management and enhance security.
Marcel van Beek · 10 min read

A warm welcome for Dylan Klümann
This month we have welcomed a new colleague 👨💻. Dylan is joining us as a Project Manager and will further specialise as an IAM consultant for our product Joinly.
Mike Fraanje · 1 min read

Why departing employees create a major security gap
Failing to offboard is not a minor oversight but a serious security and compliance threat. Automated offboarding with Joinly ensures former employees lose access, meets regulatory requirements, and cuts unnecessary license costs.
Marcel van Beek · 2 min read

Automate Joiner-Mover-Leaver provisioning in one go
Automate onboarding, transfers, and offboarding from your HR system to Entra ID/AD with Joinly.
Marcel van Beek · 2 min read

RBAC vs. ABAC: who gets the key to your digital home?
Discover the difference between RBAC and ABAC via Joinly and learn how to manage your software landscape securely and automatically with a combination of roles and attributes for optimal access management.
Marcel van Beek · 6 min read

5 common mistakes in IAM implementations (and how to avoid them)
Nathan Snippe · 3 min read

HR-driven provisioning: automate hiring, transfers, and departures
Every employee goes through a journey within the organisation: they join, sometimes change roles or departments, and eventually leave the company. At each step, access and permissions must be carefully managed. Traditionally, this often happens manually: HR registers someone, IT creates accounts, managers request additional permissions… The result? A lot of work, errors, and risks.
Morten Broers · 6 min read

Joinly by KoppelHet certified partner of AFAS
Joinly's parent company KoppelHet is a certified integration partner of AFAS.
Marcel van Beek · 1 min read

AFAS integrations: GET and UPDATE connectors
About AFAS Get and Update connectors.
Marcel van Beek · 2 min read
Entra ID

Hoe richt je access reviews in voor groepslidmaatschap?

Hoe geef je toegang tot applicaties via groepen in Entra ID?
Applicatietoegang via groepen regel je in Entra ID door de app als enterprise application te registreren, onder Properties de optie "Assignment required" op Yes te zetten, en vervolgens onder Users and groups je toegangsgroep toe te wijzen, eventueel gekoppeld aan een app role. Vanaf dat moment bepaalt het groepslidmaatschap wie de app ziet en kan gebruiken. De valkuil: alleen directe leden tellen; een geneste groep binnen je toegangsgroep krijgt níéts. Wie dit goed inricht, heeft per applicatie één plek waar toegang geregeld is. Wie het overslaat, heeft apps die voor de hele organisatie openstaan zonder dat iemand dat ooit zo besloten heeft.
Marcel van Beek · 5 min read

How do you create dynamic groups based on HR attributes?
A dynamic group in Entra ID populates itself based on a rule regarding user attributes, for example, everyone with department Finance or jobTitle Team Leader. You create it via Entra ID → Groups → New group, choose membership type Dynamic User, and build the rule in the rule builder. The group only works as well as the HR attributes it runs on: if department and job title are not reliably stored in Entra, even the best rule will not work. The latter is the real work in practice. Building the rule takes five minutes; ensuring that department, jobTitle, and employeeType are populated and up to date for every Employee is an ongoing process. This article covers both sides.
Marcel van Beek · 8 min read

What is the difference between security groups and Microsoft 365 groups?
A security group manages access: you link applications, licences, permissions, and policies to it. A Microsoft 365 group manages collaboration: upon creation, the group automatically receives a shared mailbox, a SharePoint site, a Planner, and optionally a team in Microsoft Teams. The rule of thumb is simple: if it is about who has access, choose a security group. If it is about working together in a shared environment, choose a Microsoft 365 group. In practice, this often goes wrong because both types are created in the same screen and appear identical at first glance. Choosing the incorrect type requires exporting, rebuilding, and linking once again later, as converting between the two types is not possible.
Marcel van Beek · 10 min read

How do you set up Entra ID groups for role access?
You set up role access in Entra ID by creating a security group for each job title or role that carries the access: applications, licences and data are linked to the group, never to the individual. You then populate the group automatically based on HR attributes such as department and job title, using dynamic membership rules or through provisioning from your HR system. In this article, you will read how to design the model, what choices to make and how to set it up step by step.
Marcel van Beek · 5 min read

Profit 8 Entra ID koppeling: wat de AFAS-koppeling doet en waar Joinly verder gaat
De Profit 8 Entra ID koppeling synchroniseert AFAS-gebruikersgroepen naar Entra ID. Ontdek wat de koppeling doet, waar ze stopt en hoe Joinly verder gaat.
Marcel van Beek · 6 min read
Klantverhalen

Identity & Access Management als fundament voor groei en controle bij Dael
Samen met Joinly heeft DAEL het instroom, doorstroom en uitstroom-proces geautomatiseerd. Door AFAS als betrouwbare bron te koppelen aan Active Directory en Entra ID, worden gebruikersaccounts nu automatisch aangemaakt, aangepast of gedeactiveerd op basis van HR-mutaties.
Dylan Klümann · 5 min read

Klantverhaal: Koninklijke Oosterhof Holman
Oosterhof Holman brengt met Joinly HR, IT en security samen in één gestroomlijnd proces. Door personeelsdata centraal te beheren en automatisch te synchroniseren, ontstaat er meer grip, minder handmatig werk en een solide basis voor verdere automatisering.
Dylan Klümann · 5 min read
Organisations that handed over their access management
A selection of our customers, from hospitality to aviation and from a school board to a software group with 3,000 employees. Per organisation you read how it was, what was built and what it delivers today.
- Restaurant group with several brands
- Software group with several operating companies
- Koninklijke Oosterhof Holman
- DAEL
- Care organisation with 750+ employees
- Energy company with approvals
- Utility company in the Caribbean Netherlands
- Agricultural services provider
Browsing is free
Schedule a no-obligation demo
In 30 minutes, we would love to show you how Joinly adds value for the entire organization.
Schedule a demo