When someone joins, moves or leaves in HiBob, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect HiBob to Microsoft Entra ID, Joinly reads each HR change in Bob at the source — through the HiBob Public API with a dedicated API service user — and applies it automatically to the right account. Bob stays your source of truth; Joinly is the engine that keeps every action accurate and traceable.
Key takeaways
Bob stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically.
Joinly maps Bob’s structure — site, department and team — to the right Entra ID groups and licences, something Bob’s SCIM provisioning can’t do with role-to-group logic.
Joinly tracks the Bob lifecycle status (upcoming, active, leaving), so a future-dated hire that sits as ‘upcoming’ is provisioned exactly on its start date and not missed by a default query.
Rapid scale-up reorgs — new teams, renamed sites, moved reporting lines — are handled by rule-based mapping rather than hard-coded group assignments.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | HiBob (Bob) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | HiBob Public API (service user) → Entra ID |
Supported events | Joiner, mover, leaver (incl. rehire, lifecycle status changes, team and site moves) |
Synced attributes | Name, email / UPN, site, department, team, job title, manager, start and end date |
Authentication | API service user with token, HTTP Basic auth (no employee-linked legacy token) |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync HiBob to Microsoft Entra ID?
Joinly reads each HR change in Bob through the Public API and applies it to the matching Entra ID account automatically. Bob holds the authoritative employment record, so it is the starting point for each identity action.
Joiner. HR completes the hire in Bob. Joinly reads the new profile — including the upcoming lifecycle status and effective start date — and determines the role from attributes like site, department and team. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the start date, even though Bob hides ‘upcoming’ people from default list queries.
Mover. When someone changes team, department or site in Bob, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual job — and it keeps up even when a scale-up renames teams or spins up a new site.
Leaver. When Bob moves a person to a leaving / terminated lifecycle status on the recorded end date, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and the change is tied back to the exact Bob status transition that triggered it.
Example: A fintech scale-up hires a backend engineer in Bob with a start date next Monday, attached to the Amsterdam site and the Payments team. The person sits as ‘upcoming’ and is invisible to a default API list. Joinly reads the record by lifecycle status and start date, waits until Monday, creates the Entra ID account, assigns an Office E3 licence and adds the engineer to the Payments-Eng group. When the team is later renamed in a reorg, Joinly re-evaluates the mapping rule and swaps the group without anyone editing Entra by hand.
What manual user management costs
Without automation, every account starts as a HiBob ticket or a line in a spreadsheet that IT works through by hand. Bob’s SCIM provisioning to Entra can move core attributes across, but it maps groups only to departments, doesn’t expose custom fields and has no role-to-group logic — so the part that actually decides access still falls to people.
Onboarding delays. New joiners wait for accounts, licences and group access while a ticket sits in a queue, losing productive days in their first week — and an ‘upcoming’ hire missed by a default query simply never gets created.
Permissions that don’t keep up (privilege creep). When movers change team or site, old access often stays attached, so people accumulate rights they no longer need — especially in a fast-moving scale-up that reorgs often.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — and a leaving status that nobody actions leaves an account live for weeks.
Joinly vs. HiBob’s native SCIM provisioning
Bob’s SCIM provisioning app for Entra ID is a fine baseline, but it stops short of the part that actually decides access. Here’s how the two compare for a Bob-driven setup.
Joinly | HiBob SCIM provisioning | |
|---|---|---|
Source | Reads the HiBob Public API directly | Pushes via SCIM from Bob |
Role-to-group mapping | Built in, rule-based on site / department / team | Group maps to department only; no role-to-group logic |
Upcoming / future hires | Reads by lifecycle status and times creation to the start date | ‘Upcoming’ people hidden from default queries; timing is manual |
Reorg handling | Re-evaluates mapping rules on every change | Manual remap when teams or sites change |
Custom Bob fields | Mapped via Liquid templates | Not exposed via SCIM |
On-premise AD | Yes, own agent plus the native Microsoft agent | Needs the Entra provisioning agent or middleware |
Audit trail | Per-action logging tied to the HR source | Limited |
Watch-outs when connecting HiBob to Microsoft Entra ID
A few HiBob-specific details decide whether this connection stays reliable at scale.
Lifecycle status drives access. Bob models a person as upcoming, active or leaving, and access should follow those transitions — not the moment a record is saved. A future-dated hire sits as ‘upcoming’ and is hidden from default list queries, so a naive read misses it entirely. Joinly reads by lifecycle status and effective start date, so access is ready on the right day.
Sites and teams, not classic departments. Bob structures people by site, department and team, which don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from that structure to the correct groups and licences, so role drives access rather than manual assignment.
Rapid org changes in a scale-up. Fast-growing companies rename teams, open new sites and reshuffle reporting lines constantly. Hard-coded group assignments rot quickly. Joinly re-evaluates rule-based mappings on every sync, so the org chart and Entra access stay in step.
UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, site code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Custom Bob fields and termination reasons. Custom HiBob fields aren’t exposed by SCIM, and Bob expects termination reasons from its configured list. Joinly maps the custom fields you need via Liquid templates and reads the exact status and reason that triggered each action.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which HiBob change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a fintech scale-up with around 900 employees across four sites, running Bob as its HR core while its identity provisioning never quite keeps up. Bob’s SCIM app handles the simple cases, yet rapid hiring, a constant stream of team renames and new sites keep breaking it — future-dated engineers sit as ‘upcoming’ and never get an account until someone notices, and a department-only group map leaves new Payments and Risk teams with no access rule at all.
Connect HiBob to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change in Bob at the source and acts on it automatically: new hires have their account, Office licence and group access ready on their start date even while they’re still ‘upcoming’, team and site moves swap the right groups the same day, reorgs are absorbed by rule-based mapping, and leavers are disabled the moment Bob flips them to a leaving status, with a 30-day soft-delete grace window.
“Upcoming hires used to fall through the cracks and every reorg meant re-doing group maps by hand. Now an account is simply ready on the start date, a renamed team just re-maps itself, and we can show the auditor exactly which Bob change created every bit of access.”
The outcome this setup is designed for: onboarding drops from days to zero touch, no ‘upcoming’ hire is ever missed, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone HiBob to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect HiBob to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the HiBob integration in the Joinly marketplace
Open the Joinly marketplace and search for the HiBob integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the HiBob integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your HiBob connection details: the API service user ID and token you generated in Bob (Settings → Integrations → API service users), with the People permissions assigned. We only ask for the information needed to establish a successful connection with HiBob. All data is encrypted and stored securely.

Enter your HiBob API service user ID and token in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Bob fields.
Frequently asked questions
How do I map the manager? Reference the manager’s Bob employee ID in the mapping and Joinly resolves the link to the right manager automatically.
How do I handle upcoming hires? Joinly reads people by lifecycle status and start date, so a person still marked ‘upcoming’ in Bob is picked up and provisioned on the correct day.
How do I prevent duplicate usernames? Use the generateUniqueUsername helper, which falls back to the next pattern when the first one is already taken: {{ generateUniqueUsername: \

Map HiBob fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from HiBob should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Bob flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the end date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting HiBob to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the HiBob to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Bob reach Entra ID quickly without waiting for a nightly batch.
How does Joinly handle upcoming (future-dated) hires in Bob?
Bob marks a future hire as ‘upcoming’ and hides it from default list queries. Joinly reads people by lifecycle status and start date, so the account is created on the start date rather than missed or created too early.
How does Joinly cope with a scale-up that reorgs often?
Group and licence assignment is rule-based on site, department and team, so when Bob renames a team, opens a new site or moves reporting lines, Joinly re-evaluates the rules on the next sync instead of needing a manual remap.
Which attributes sync from HiBob to Entra ID?
Name, email / UPN, site, department, team, job title, manager, and start and end date. Custom Bob fields that SCIM doesn’t expose can be mapped via Liquid templates.
Do I still need Bob’s native SCIM provisioning?
No. Joinly takes over the provisioning, role-to-group mapping and lifecycle-status handling that SCIM does only partially, and maintains it as your Bob data changes.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the HiBob to Active Directory guide.


