When someone joins, moves or leaves in Fluida, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Fluida to Microsoft Entra ID, Joinly reads each change in the Fluida people directory at the source — through the Fluida API with a read-only key — and applies it automatically to the right account. Fluida stays your source of truth for who works where; Joinly is the engine that keeps every account accurate and traceable.
Key takeaways
Fluida stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically from the Fluida people directory.
Joinly maps Fluida’s own structure — Sede, Reparto and Team — to the right Entra ID groups and licences, something an attendance app was never built to do on its own.
Joinly connects with a scoped read-only Fluida API key, so provisioning only ever reads the data it needs and never writes back to your HR platform.
Because Fluida is attendance- and shift-driven, Joinly resolves the UPN carefully for frontline staff who may not have a work email, so every account has a unique, predictable sign-in.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | Fluida (people directory / Rubrica aziendale) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Fluida API → Entra ID |
Authentication | Fluida API key (Read Only), created under Company > Generals > API |
Supported events | Joiner, mover, leaver (based on people, Sede, Reparto and Team changes) |
Synced attributes | Name, email / UPN, Sede (office), Reparto (department), Team, job title, manager, start and end date |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Fluida to Microsoft Entra ID?
Joinly reads each change in Fluida through the API and applies it to the matching Entra ID account automatically. The Fluida people directory holds who works where — in which Sede, Reparto and Team — so it is the starting point for each identity action.
Joiner. HR adds the person in Fluida and assigns them to a Sede, Reparto and Team. Joinly reads the new record on its next sync, determines the role from those fields, then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups.
Mover. When someone changes Sede, Reparto or Team in Fluida, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new assignment is revoked, so permissions stay aligned with where the person actually works.
Leaver. When the person is set to leave in Fluida — or their end date passes — Joinly disables the Entra ID account automatically. No orphaned accounts are left active after someone has gone, and licences are freed up.
Example: A hospitality group runs Fluida for attendance and shifts across four hotels. It adds a new front-desk agent in Fluida, assigned to the Milano Sede and the Reception Reparto. On the next sync Joinly creates the Entra ID account, assigns a Microsoft 365 Business licence and adds the agent to the Milano-Reception group. When that agent later transfers to the Roma property, Joinly moves them out of the Milano groups and into the Roma ones the same day.
What manual user management costs
Without automation, every account starts as a message from HR — a line in a shift plan or a Fluida notification — that IT works through by hand. Fluida is excellent at attendance, shifts and leave, but it was never meant to drive Entra ID: there is no native connector, so the native alternative is to build a SCIM client against Microsoft’s API-driven inbound provisioning yourself. Until then, the part that actually decides access falls to people.
Onboarding delays. New joiners — often frontline staff who need access on day one of a shift — wait for accounts, licences and group access while a request sits in a queue.
Permissions that don’t keep up (privilege creep). When movers change Sede or Reparto, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — a real problem in high-turnover, shift-based teams.
Joinly vs. native Entra API-driven provisioning
There is no packaged Fluida connector for Entra ID. The native route is Microsoft’s API-driven inbound provisioning — you build and run a SCIM client that reads Fluida and bulk-uploads to Entra ID. Here’s how that compares to Joinly for a Fluida-driven setup.
Joinly | Native Entra API-driven provisioning | |
|---|---|---|
Source | Reads the Fluida API directly with a read-only key | You build a custom SCIM client to read Fluida |
Role-to-group mapping | Built in, rule-based on Sede, Reparto and Team | Attribute mapping only; no role-to-group out of the box |
Frontline staff without email | Custom UPN rules with a uniqueness fallback | Left to the SCIM payload you construct |
Development effort | No code; configured in the platform | Custom SCIM development and hosting, subject to Entra throttling limits |
Licence assignment | Driven by role / attributes | Manual or group-based only |
On-premise AD | Yes, own agent plus the native Microsoft agent | Provisioning agent required, limited mapping |
Audit trail | Per-action logging tied to the HR source | Limited |
Watch-outs when connecting Fluida to Microsoft Entra ID
A few Fluida-specific details decide whether this connection stays reliable in a shift-based, SME setting.
Fluida is attendance-driven, not a full HRIS. Fluida models people through their Sede, Reparto and Team rather than a rich contract or position hierarchy. Joinly builds explicit rules from those fields to the right Entra groups and licences, so an attendance app becomes a reliable joiner-mover-leaver source.
Frontline staff without a work email. In hospitality and other shift-based teams, many people are identified by badge or personal contact rather than a company mailbox. Joinly applies custom UPN rules — from name plus Sede code or a controlled tiebreaker — so every account still gets a unique, predictable sign-in.
Read-only, scheduled sync. Fluida’s API is export- and integration-oriented, so Joinly connects with a Read Only API key and reads the directory on a frequent schedule rather than assuming push events. Provisioning stays current without ever writing back to Fluida.
Mapping Sedi and Reparti to Entra groups. A Sede or Reparto doesn’t translate one-to-one to an Entra ID group. Joinly builds explicit mapping rules from those structures to the correct groups and licences, so role drives access rather than manual assignment.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Fluida change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a hospitality group with around 350 employees across four hotels, running Fluida for attendance, shifts and leave while its identity provisioning never quite keeps up. With high seasonal turnover and staff moving between properties, every new receptionist, housekeeper or kitchen hire is an email to IT — and with no native Fluida-to-Entra connector, accounts are created by hand, licences are guessed at, and leavers linger long after their last shift.
Connect Fluida to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each change in the Fluida people directory at the source and acts on it automatically: new hires have their account, Microsoft 365 licence and group access ready for their first shift, a move from one hotel to another swaps the right groups the same day, staff without a work email still get a unique, predictable UPN, and leavers are disabled with a soft-delete grace window.
“We hire in waves for the season, and IT used to be the bottleneck. Now a new receptionist is simply ready on their first shift, a transfer between hotels just swaps their access, and we can show exactly which Fluida change created every account.” — Head of IT, hospitality group
The outcome this setup is designed for: onboarding drops from days to zero touch, seasonal leavers are cleaned up automatically, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone Fluida to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Fluida to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the Fluida integration in the Joinly marketplace
Open the Joinly marketplace and search for the Fluida integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Fluida integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Fluida connection details: a Read Only API key, which you create in Fluida under Company > Generals > API by adding a new key, giving it a name and enabling it. We only ask for the information needed to establish a successful connection with Fluida. All data is encrypted and stored securely.

Enter your Fluida Read Only API key in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Fluida fields like Sede, Reparto and Team.
Frequently asked questions
How do I map the department? Reference the Reparto field in the mapping and route it to the right Entra group.
How do I handle staff without a work email? Build the UPN from name plus a Sede code so every frontline account still gets a unique sign-in.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{lastName}”, “{firstName}.{initials}.{lastName}” }}

Map Fluida fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Fluida should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Fluida flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the end date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Fluida to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Fluida to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in the Fluida people directory reach Entra ID quickly without waiting for a nightly batch.
How does Joinly connect to Fluida?
With a Read Only API key that you create in Fluida under Company > Generals > API. Joinly only ever reads the people directory it needs and never writes back to Fluida.
Is there a native Fluida connector for Entra ID?
No. Fluida is an attendance and shift platform with no packaged identity-provider connector, so the native alternative is to build a SCIM client against Microsoft’s API-driven inbound provisioning yourself. Joinly reads Fluida directly and does the role-to-group mapping and licensing for you, with no code.
Which attributes sync from Fluida to Entra ID?
Name, email / UPN, Sede (office), Reparto (department), Team, job title, manager, and start and end date. Additional Fluida fields can be mapped via Liquid templates.
How do you handle frontline staff without a work email?
Joinly builds the UPN from your rules — for example name plus a Sede code — with a uniqueness fallback, so every account gets a unique, predictable sign-in even when the person has no company mailbox in Fluida.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Fluida to Active Directory guide.


