Overig · Overig
Why departing employees create a major security gap
Failing to offboard is not a minor oversight but a serious security and compliance threat. Automated offboarding with Joinly ensures former employees lose access, meets regulatory requirements, and cuts unnecessary license costs.

Marcel van Beek · IAM Consultant · 2 min read
An employee leaves, but their Microsoft 365 and SaaS accounts remain active. It might seem harmless, but it opens the door to data breaches and compliance violations.
🔓 What Can Go Wrong
Unauthorized access – Former employees can still reach email, Teams, CRM, or customer data.
Shadow IT – Forgotten accounts can be exploited for illegal access or phishing attacks.
Compliance violations – GDPR and ISO 27001 require immediate revocation of access when employment ends.
Cost leakage – Licenses and cloud services continue to run, adding unnecessary subscription costs.
How It Happens
Manual processes, shared mailboxes, multiple SaaS apps, and a lack of centralized identity management make it easy to overlook accounts. Growing organizations lose track quickly.
🛡️ The Solution: Automated Offboarding
HR as the source of truth – The HR system holds the official termination date.
Automatic de-provisioning – Joinly connects HR to Entra ID/AD and disables accounts as soon as an employee leaves.
Reporting & logging – Provides evidence for auditors and internal controls.
✅ Implementation with Joinly
Connect HR and Entra ID/AD for real-time signaling.
Configure a leaver flow to revoke all linked apps and licenses.
Review regularly with reports to ensure no “orphan accounts” remain.
Conclusion
Failing to offboard is not a minor oversight but a serious security and compliance threat.
Automated offboarding with Joinly ensures former employees lose access, meets regulatory requirements, and cuts unnecessary license costs.
Explore more blogs

Segregation of Duties (SoD): wat het is en hoe je het afdwingt
Wat is segregation of duties (functiescheiding)? Uitleg, voorbeelden en waarom het vaak misgaat. Plus hoe je SoD-conflicten automatisch tegenhoudt.
Marcel van Beek · 4 min read

How do you apply AGDLP in a hybrid Entra/AD environment? (And why you shouldn't want to anymore)
Short answer: preferably not. AGDLP (Accounts → Global groups → Domain Local groups → Permissions) is a concept from the era of manual management. The entire nesting construction exists for one reason: to allow a human to assign permissions with as few mouse clicks as possible. As soon as an agent assigns group memberships directly based on HR data, this reason disappears and only the complexity remains. Moreover, in a hybrid environment, this complexity actively works against you, because Entra ID completely ignores nesting for licences and app assignment. In this article, you can read how AGDLP works and why it was once smart, where it breaks down in a hybrid environment, and what the modern alternative looks like: direct memberships, managed by automation.
Marcel van Beek · 5 min read

How do I set up role-based access control (RBAC) and least privilege for a municipality?
Start with the roles in your HR system and map them to roles, not to individual permissions per person. Group each role with precisely the access required for the job, adhering to the principle of least privilege. Manage these roles centrally and let an orchestration layer automatically assign and revoke them. This keeps access predictable, limited and demonstrable.
Mike Fraanje · 4 min read
See what Joinly can do for your organisation?
Start a free trial today or get in touch for advice on your HR and Microsoft environment.