Skip to main content
Joinly by KoppelHet

Workday · comparison

Workday to Entra ID and Active Directory: Joinly vs Microsoft's native provisioning

Workday is one of the two HR systems Microsoft wrote its own connector for. So the question is fair: what does Joinly add? The short version — the connector moves users, Joinly decides what those users should have, on both sides of a hybrid environment, with a brake and a log. The long version is below.

Workday

What Microsoft gives you for Workday

Microsoft ships an inbound provisioning connector for Workday. The Entra provisioning service reads Workday itself and writes users to Microsoft Entra ID, or — through the Microsoft Entra provisioning agent — to on-premise Active Directory. Attribute mappings and scoping filters are configured in the Entra admin centre. What happens around the account (groups, licences, the leaver process) is not part of the connector: Microsoft positions Lifecycle Workflows, part of Entra ID Governance, for that.

What Joinly adds

Joinly starts where the Microsoft route starts, at Workday, and goes further on both ends.

  • A ready-made Workday import plugin, reading the Workday REST / RAAS API — no client to build or host.
  • The rules: which department, job, location or legal entity maps to which groups, licences and organisational unit. Microsoft's mappings move attributes; Joinly's rules decide access, and record the reason per assignment.
  • Both directories from one source: Entra ID through Microsoft Graph, on-premise Active Directory through the Joinly AD Agent (outbound only, no provisioning agent to install and no inbound rules), so hybrid organisations do not run two pipelines.
  • A brake: a dry run with an Excel export, thresholds per run, read-only mode, and a hard stop when an evaluation would revoke more than 20% of assignments at once.
  • Beyond the directory: shared mailbox, out-of-office, SharePoint and Teams, a ticket in TOPdesk or Freshservice, an SMS with the first-day credentials, a webhook to any application — as steps in the same workflow.
  • An audit log per mutation with its source and the workflow that caused it, which is the evidence an ISO 27001 or NIS2 auditor asks for.

Side by side

Microsoft's routeJoinly
Workday connectorNative inbound provisioning connectorReady-made import plugin
Who decides accessAttribute mappings; joiner/leaver tasks through Lifecycle Workflows (Entra ID Governance)Role rules on department, job and location, with the reason recorded per assignment
On-premise Active DirectoryMicrosoft Entra provisioning agentJoinly AD Agent, outbound HTTPS only, OU and groups included
Before anything is writtenProvision on demand for a single userDry run with Excel export, thresholds, read-only mode, 20% brake
Beyond the directoryLifecycle Workflows tasks and custom extensionsExchange, SharePoint, Teams, TOPdesk, Freshservice, SMS, webhooks in one workflow
LicensingEntra ID P1/P2; Governance for Lifecycle WorkflowsJoinly subscription; the Microsoft Graph path needs no P1 or P2
EvidenceProvisioning logsAudit log per mutation, with source and workflow

When Microsoft's route is enough

If Entra ID is your only target, your team is at home in the Entra admin centre and Lifecycle Workflows, and access beyond birthright groups is handled elsewhere, the native Workday connector can carry you. Be honest about the mover: a change of department in Workday updates an attribute, and something still has to translate that into the right groups.

When you want Joinly

When there is an on-premise Active Directory next to Entra ID. When the answer to "why does this person have this group" has to come from a rule, not a memory. When you want to see what a run would do before it does it. When offboarding has to reach the mailbox, SharePoint and the service desk, not just the account. And when an auditor will ask for the log.

Can I use both?

Yes. Joinly can deliver its result to Microsoft's API-driven provisioning endpoint as SCIM 2.0 bulk requests — to Entra ID or, through the provisioning agent, to Active Directory. Then Joinly reads Workday and applies the rules, and the Entra provisioning service does the write. The SCIM page for Workday describes that route.

Frequently asked

Questions about Workday

  • Does Microsoft have a native connector for Workday?

    Yes. Workday is one of the two HR systems (with SAP SuccessFactors) that Microsoft ships an inbound provisioning connector for, to Entra ID and to on-premise Active Directory through the provisioning agent.

  • Does Joinly replace Entra ID?

    No. Entra ID stays your directory and identity provider. Joinly sits between Workday and Entra ID (and Active Directory) and decides what each account should have, applies it, and records why.

  • Do I need Entra ID P1 or P2 for Joinly?

    Not for the Microsoft Graph path, which uses Joinly's own app registration. Microsoft's API-driven provisioning endpoint requires Entra ID P1, P2 or Governance; if you choose that route, that licensing applies.

  • Can I start with the Workday guide and decide later?

    Yes. Both installation guides for Workday are public, and a trial lets you run the import as a dry run against your own data before anything is written.

See what Joinly can do for your organisation?

Start a free trial today or get in touch for advice on your HR and Microsoft environment.