Skip to main content
Joinly by KoppelHet

Lucca · Microsoft Entra ID · Active Directory

Connect Lucca to Microsoft Entra ID and Active Directory

When someone joins, moves or leaves in Lucca, Joinly makes the matching change in Entra ID and Active Directory — account, groups, licences, manager, and on the termination date the account goes closed. Lucca stays the source of truth; Joinly is the engine that applies it and keeps the evidence.

Lucca

What Joinly does with Lucca

Joinly reads each HR change through the Lucca API (/api/v3/users, /api/v3/departments) and turns it into the actions your rules prescribe. The events it handles: joiner, mover, leaver (incl. rehire and internal transfer). Lucca is a ready-made import plugin in Joinly: enable it, enter the endpoint of your Lucca environment, done.

The rules are the part no connector decides for you: which department, job or location maps to which groups, licences and organisational unit. That mapping lives in Joinly, is configurable per field with Liquid templates, and can be previewed on real employees before anything is applied.

Two directories, one source

To Microsoft Entra ID, Joinly talks through Microsoft Graph with its own app registration: it creates, updates, enables and disables accounts, assigns and revokes licences, sets group memberships and the manager, issues a Temporary Access Pass for the first day and, at the end, revokes sessions and soft-deletes the account.

To on-premise Active Directory, the Joinly AD Agent runs inside your network and polls Joinly for work over outbound HTTPS — no inbound firewall rule, no VPN. It creates the user in the right OU, builds the sAMAccountName and UPN from your rules, manages security groups and can create an Exchange remote mailbox in a hybrid setup. Hybrid organisations run both connections from the same Lucca source.

Beyond the directory

Most leavers are not finished when the account is disabled. Joinly's workflows also convert the mailbox to a shared mailbox, set an out-of-office, clear the calendar, remove SharePoint permissions and Teams memberships, raise an incident in TOPdesk or a request in Freshservice, and call any application that accepts a webhook. Each step waits for the previous one to succeed.

Safe to switch on

Every import can run as a dry run with an Excel export of what would happen. Thresholds cap how many creations, activations and deactivations one run may produce before it is blocked for approval, and an access evaluation that would revoke more than 20% of assignments in one go stops itself. Until you trust it, the connection can run in read-only mode: everything is calculated, nothing is written.

Frequently asked

Questions about Lucca

  • Is Lucca supported out of the box?

    Yes. Lucca is a ready-made HR connector in Joinly. You enable it, enter the details of your Lucca environment and Joinly reads the employees from there. The dry run, thresholds and matching strategies are the same as for every other source.

  • Can Lucca feed both Entra ID and an on-premise Active Directory?

    Yes. One HR source can drive both connections at the same time, plus your business applications and ITSM tool. Hybrid organisations use that so cloud and on-premise follow the same truth, with one audit log across both.

  • Does Microsoft not already do this for Lucca?

    Not natively. For Lucca, Microsoft offers API-driven inbound provisioning: an endpoint that accepts SCIM bulk requests, provided you build and run the client that reads Lucca and packages the data. Joinly is that client and the rules layer on top of it, and it can also write through Microsoft Graph directly. The comparison page walks through both routes.

  • Where does the data live?

    Joinly runs in the EU and is ISO 27001-certified. Every mutation is recorded in the audit log with its source — HR import, manual, from Entra, by the system or through an API key — and a link to the workflow that caused it.

See what Joinly can do for your organisation?

Start a free trial today or get in touch for advice on your HR and Microsoft environment.