Overig · Overig
Automate Joiner-Mover-Leaver provisioning in one go
Automate onboarding, transfers, and offboarding from your HR system to Entra ID/AD with Joinly.
Marcel van Beek · IAM Consultant · 2 min read
Automate Joiner-Mover-Leaver provisioning at once
Imagine: a new colleague starts tomorrow. No tickets, no night work for IT—his Microsoft account, Teams memberships, and 365 licenses are already set up. That is the effect of HR-driven identity automation.
🚀 Why it can be different
Manual user management is slow and error-prone. The HR system is the first to know who starts, moves, or leaves. Use that as the single source of truth and let Entra ID and AD automatically adjust.
🧩 How it works with Joinly
Plug & Play integration – Choose your HR package (AFAS, Visma, Nmbrs, Workday…) and connect via the Joinly dashboard.
Intelligent mapping – Map HR fields (department, role, end date) to Entra attributes.
Realtime provisioning – As soon as HR changes anything, Joinly pushes the update to Entra ID and on-prem AD.
Zero-touch management – Joiners gain instant access, movers get the right permissions, leavers lose access on the exact end date.
⚡️ What you gain
Less risk – No forgotten accounts or shadow access.
Faster onboarding – New employees are live within minutes.
Scalable – Whether you have 50 or 5,000 employees.
Ready to automate
With Joinly, you centralise your HR system as the identity source and let Microsoft Entra ID and Active Directory do the work. Less management, less risk, more control.
Explore more blogs

Segregation of Duties (SoD): wat het is en hoe je het afdwingt
Wat is segregation of duties (functiescheiding)? Uitleg, voorbeelden en waarom het vaak misgaat. Plus hoe je SoD-conflicten automatisch tegenhoudt.
Marcel van Beek · 4 min read

How do you apply AGDLP in a hybrid Entra/AD environment? (And why you shouldn't want to anymore)
Short answer: preferably not. AGDLP (Accounts → Global groups → Domain Local groups → Permissions) is a concept from the era of manual management. The entire nesting construction exists for one reason: to allow a human to assign permissions with as few mouse clicks as possible. As soon as an agent assigns group memberships directly based on HR data, this reason disappears and only the complexity remains. Moreover, in a hybrid environment, this complexity actively works against you, because Entra ID completely ignores nesting for licences and app assignment. In this article, you can read how AGDLP works and why it was once smart, where it breaks down in a hybrid environment, and what the modern alternative looks like: direct memberships, managed by automation.
Marcel van Beek · 5 min read

How do I set up role-based access control (RBAC) and least privilege for a municipality?
Start with the roles in your HR system and map them to roles, not to individual permissions per person. Group each role with precisely the access required for the job, adhering to the principle of least privilege. Manage these roles centrally and let an orchestration layer automatically assign and revoke them. This keeps access predictable, limited and demonstrable.
Mike Fraanje · 4 min read
See what Joinly can do for your organisation?
Start a free trial today or get in touch for advice on your HR and Microsoft environment.