Overig · Overig
What is Identity and Access Management (IAM)-2?
Companies are digitising rapidly. HR-systems, SaaS-tools, customer portals, mobile apps – everyone works with accounts, logins, and permissions. But who actually keeps an overview of who has access to what? Exactly there, Identity & Access Management (IAM) comes into play.
Companies are digitalising rapidly. HR systems, SaaS tools, customer portals, mobile apps – everyone works with accounts, logins, and permissions. But who actually keeps track of who has access to what?
This is exactly where Identity & Access Management (IAM) comes into play.
What is IAM?
IAM manages everything around digital identities: creating accounts, granting permissions, and revoking them once someone leaves or changes roles.
The goal: the right person, the right access, at the right time.
Or to put it simply: everyone inside (or outside) your organisation gets exactly what they need, and nothing more.
Why it is indispensable
Without proper IAM, chaos quickly arises: old accounts remain active, temporary employees retain access to customer data, and no one knows whether someone should or should not have access to that one HR system.
This is not only a risk for your security, but also for compliance. Consider the GDPR, which requires you to demonstrate that personal data is only accessible to authorised users.
IAM ensures:
Security: no open accounts or overly broad permissions.
Compliance: everything is traceable and auditable.
Efficiency: no more manual account management, but automatic provisioning from HR.
User-friendliness: one login (SSO) for all applications.
From HR to IT: the logical foundation
In many organisations, the lifecycle of an employee starts in HR.
Therefore, it makes sense to make IAM HR-driven.
New employee joining? Joinly sees it directly in the HR system and automatically creates the right account in Microsoft Entra (Azure AD), Teams, and other linked apps.
Someone leaving? Access is automatically revoked. No separate Excel sheets, no forgotten accounts.
What is IAM in 2025: from control to trust
IAM is no longer an IT chore. It is a strategic tool for organisations that want to work safely, scalably, and future-proof.
With concepts like Zero Trust and least privilege, the focus shifts from ‘trust unless’ to ‘verify unless’.
IAM forms the technological backbone: every user, every request, and every access is checked, logged, and managed.
The role of Joinly
Joinly makes IAM accessible for organisations that do not want to get lost in complicated policies and expensive licenses.
Our approach is simple:
HR is the source of truth
IAM automates access via Entra ID
Governance, logging, and self-service are built-in
Thus, you make access secure, demonstrable, and manageable – without overloading your IT team.
Summary
IAM is the silent force behind secure digital collaboration.
It prevents employees from having too many permissions, keeps compliance in check, and ensures that onboarding and offboarding happen automatically.
In short: IAM is not just an IT topic, but an essential part of how modern organisations work.
Explore more blogs

Segregation of Duties (SoD): wat het is en hoe je het afdwingt
Wat is segregation of duties (functiescheiding)? Uitleg, voorbeelden en waarom het vaak misgaat. Plus hoe je SoD-conflicten automatisch tegenhoudt.
Marcel van Beek · 4 min read

How do you apply AGDLP in a hybrid Entra/AD environment? (And why you shouldn't want to anymore)
Short answer: preferably not. AGDLP (Accounts → Global groups → Domain Local groups → Permissions) is a concept from the era of manual management. The entire nesting construction exists for one reason: to allow a human to assign permissions with as few mouse clicks as possible. As soon as an agent assigns group memberships directly based on HR data, this reason disappears and only the complexity remains. Moreover, in a hybrid environment, this complexity actively works against you, because Entra ID completely ignores nesting for licences and app assignment. In this article, you can read how AGDLP works and why it was once smart, where it breaks down in a hybrid environment, and what the modern alternative looks like: direct memberships, managed by automation.
Marcel van Beek · 5 min read

How do I set up role-based access control (RBAC) and least privilege for a municipality?
Start with the roles in your HR system and map them to roles, not to individual permissions per person. Group each role with precisely the access required for the job, adhering to the principle of least privilege. Manage these roles centrally and let an orchestration layer automatically assign and revoke them. This keeps access predictable, limited and demonstrable.
Mike Fraanje · 4 min read
See what Joinly can do for your organisation?
Start a free trial today or get in touch for advice on your HR and Microsoft environment.