SAP SuccessFactors · Microsoft Entra ID · Active Directory
Connect SAP SuccessFactors to Microsoft Entra ID and Active Directory
When someone joins, moves or leaves in SAP SuccessFactors, Joinly makes the matching change in Entra ID and Active Directory — account, groups, licences, manager, and on the termination date the account goes closed. SAP SuccessFactors stays the source of truth; Joinly is the engine that applies it and keeps the evidence.

What Joinly does with SAP SuccessFactors
Joinly reads each HR change through the Employee Central OData API and turns it into the actions your rules prescribe. The events it handles: joiner, mover, leaver (incl. rehire, worker conversion, concurrent employment). SAP SuccessFactors is a ready-made import plugin in Joinly: enable it, enter the endpoint of your SAP SuccessFactors environment, done.
The rules are the part no connector decides for you: which department, job or location maps to which groups, licences and organisational unit. That mapping lives in Joinly, is configurable per field with Liquid templates, and can be previewed on real employees before anything is applied.
Two directories, one source
To Microsoft Entra ID, Joinly talks through Microsoft Graph with its own app registration: it creates, updates, enables and disables accounts, assigns and revokes licences, sets group memberships and the manager, issues a Temporary Access Pass for the first day and, at the end, revokes sessions and soft-deletes the account.
To on-premise Active Directory, the Joinly AD Agent runs inside your network and polls Joinly for work over outbound HTTPS — no inbound firewall rule, no VPN. It creates the user in the right OU, builds the sAMAccountName and UPN from your rules, manages security groups and can create an Exchange remote mailbox in a hybrid setup. Hybrid organisations run both connections from the same SAP SuccessFactors source.
Beyond the directory
Most leavers are not finished when the account is disabled. Joinly's workflows also convert the mailbox to a shared mailbox, set an out-of-office, clear the calendar, remove SharePoint permissions and Teams memberships, raise an incident in TOPdesk or a request in Freshservice, and call any application that accepts a webhook. Each step waits for the previous one to succeed.
Safe to switch on
Every import can run as a dry run with an Excel export of what would happen. Thresholds cap how many creations, activations and deactivations one run may produce before it is blocked for approval, and an access evaluation that would revoke more than 20% of assignments in one go stops itself. Until you trust it, the connection can run in read-only mode: everything is calculated, nothing is written.
Frequently asked
Questions about SAP SuccessFactors
Is SAP SuccessFactors supported out of the box?
Yes. SAP SuccessFactors is a ready-made HR connector in Joinly. You enable it, enter the details of your SAP SuccessFactors environment and Joinly reads the employees from there. The dry run, thresholds and matching strategies are the same as for every other source.
Can SAP SuccessFactors feed both Entra ID and an on-premise Active Directory?
Yes. One HR source can drive both connections at the same time, plus your business applications and ITSM tool. Hybrid organisations use that so cloud and on-premise follow the same truth, with one audit log across both.
Does Microsoft not already do this for SAP SuccessFactors?
Partly. Microsoft ships an inbound provisioning connector for SAP SuccessFactors that writes users to Entra ID or, through the provisioning agent, to Active Directory. What it does not decide is which access those users should have, and it stops at the directory. The comparison page walks through the difference.
Where does the data live?
Joinly runs in the EU and is ISO 27001-certified. Every mutation is recorded in the audit log with its source — HR import, manual, from Entra, by the system or through an API key — and a link to the workflow that caused it.
Read next
Installation guides
About this HR system
- SAP SuccessFactors: Joinly vs Microsoft's native provisioningDo you need this, or does Entra ID already do it?
- SAP SuccessFactors offboarding automationFrom termination date in HR to a closed account.
- SAP SuccessFactors SCIM provisioning to Entra IDThe route through Microsoft's API-driven inbound provisioning.
- SAP SuccessFactors integrationThe connector page, with the lifecycle and the customer story.
See what Joinly can do for your organisation?
Start a free trial today or get in touch for advice on your HR and Microsoft environment.