Connect Lessor to Microsoft Entra ID

Connect Lessor to Microsoft Entra ID

Connect Lessor to Microsoft Entra ID

When someone joins, moves or leaves in Lessor, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Lessor to Microsoft Entra ID, Joinly reads each HR change at the source — from your Lessor employee master data in Emply People — and applies it automatically to the right account. Lessor stays your source of truth; Joinly is the engine that keeps every action accurate and traceable.

Key takeaways

  • Your Lessor HR record stays the source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically, so payroll and identity stay in step.

  • Joinly reads employee master data through the Emply People API (Lessor / Paychex Europe HR core) and maps Danish structures — afdeling, stilling and organisation — to the right Entra ID groups and licences.

  • There is no native Entra provisioning app for Lessor, so without Joinly this is manual work or a generic middleware bridge; Joinly adds the role-to-group logic that plain attribute sync leaves out.

  • The CPR-nummer is treated as sensitive data and is never used to build a UPN or username; Danish characters (æ, ø, å) and duplicate surnames are transliterated and de-duplicated automatically.

  • Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001, from an EU data centre.

Lessor

Joiner

Mover

Leaver

Microsoft Entra ID (formerly Azure AD)

Quick facts

Source system

Lessor (LessorLøn / Emply People HR data)

Target system

Microsoft Entra ID (formerly Azure AD)

Connection method

Lessor / Emply People API → Entra ID

Supported events

Joiner, mover, leaver (incl. rehire and department transfer)

Synced attributes

Name, email / UPN, department (afdeling), job title (stilling), manager, start and end date

Authentication

API key against the Emply People API (api.emply.com); CPR excluded from directory attributes

Real-time or batch

Frequent sync, multiple times per day

Compliance

ISO 27001, NIS2-ready, GDPR (EU data centre)

How does Joinly sync Lessor to Microsoft Entra ID?

Joinly reads each HR change from your Lessor employee master data — held in Emply People, the Lessor / Paychex Europe HR core — and applies it to the matching Entra ID account automatically. Lessor holds the authoritative employment record, so it is the starting point for each identity action.

  1. Joiner. HR registers the new medarbejder in Lessor. Joinly reads the new employee record and determines the role from attributes like afdeling (department) and stilling (position). It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the registered start date.

  2. Mover. When someone changes stilling or afdeling in Lessor, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual job rather than drifting over time.

  3. Leaver. On the end date recorded in Lessor, Joinly disables the Entra ID account automatically. No orphaned accounts are left active after someone has left, and access is removed on the date HR recorded rather than whenever a ticket is finally processed.

Example: A Danish wholesaler registers a new purchaser in Lessor with a start date next Monday, in its Copenhagen afdeling. Joinly reads the record, waits until the start date, creates the Entra ID account, assigns an Office E3 licence and adds the purchaser to the DK-Purchasing group. The CPR-nummer stays in Lessor and never touches the UPN; the login is built from the person’s name with a transliteration rule so the Danish characters resolve cleanly.

What manual user management costs

Without automation, every account starts as a message from payroll or a line in a spreadsheet that IT works through by hand. Because there is no native Entra provisioning app for Lessor, teams either key each account in manually or wire up a generic middleware export that pushes attributes but can’t decide access — so the part that actually grants the right groups and licences still falls to people.

  • Onboarding delays. New joiners wait for accounts, licences and group access while a request sits in a queue, losing productive days in their first week.

  • Permissions that don’t keep up (privilege creep). When movers change stilling or afdeling, old access often stays attached, so people accumulate rights they no longer need.

  • Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money long after someone has left.

Joinly vs. a generic middleware bridge

Lessor has no first-party Entra ID provisioning app, so the usual alternatives are a manual process or a generic middleware / IGA export. Those move attributes across, but they stop short of the part that actually decides access. Here’s how the two compare for a Lessor-driven setup.


Joinly

Generic middleware / CSV bridge

Source

Reads Lessor / Emply People data directly

Reads a generic export or middleware feed

Role-to-group mapping

Built in, rule-based on afdeling and stilling

Attribute copy only; no role-to-group out of the box

Future-dated hires

Times account creation to the recorded start date

Usually created on import, not on the start date

Licence assignment

Driven by role / attributes

Manual or group-based only

Danish data (CPR, æ/ø/å)

CPR excluded, names transliterated and de-duplicated

Left to manual configuration

On-premise AD

Yes, own agent plus the native Microsoft agent

Extra tooling required

Audit trail

Per-action logging tied to the HR source

Limited

Watch-outs when connecting Lessor to Microsoft Entra ID

A few Lessor-specific details decide whether this connection stays reliable and compliant.

  • Where the identity data actually lives. LessorLøn and Lessor5 are Danish payroll-first systems built around CPR and pay rules, not directory identity. The name, afdeling, stilling and dates you need for provisioning usually sit in Emply People, the HR core. Joinly reads from the right source so identity follows the HR record, not the payroll run.

  • CPR-nummer is sensitive data. The Danish CPR-nummer is regulated personal data and must never leak into a UPN, username or group name. Joinly keeps CPR inside Lessor as a matching key only and builds the UPN from name and organisation attributes instead.

  • Danish characters and duplicate names. Names with æ, ø or å and common Danish surnames produce collisions and invalid logins if handled naively. Joinly applies transliteration and a uniqueness fallback, so every UPN is valid, readable and unique from day one.

  • Mapping afdeling and stilling to Entra groups. Danish department and position structures don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from afdeling and stilling to the correct groups and licences, so role drives access rather than manual assignment.

Joinly handles each of these by default with custom mapping and transformation.

Always audit-ready

Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Lessor change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.

Example case

Picture a Danish wholesale distributor with around 900 employees across a head office and four regional depots, running Lessor for payroll and Emply People as its HR core while identity never quite keeps up. New buyers, warehouse staff and sales reps are registered in Lessor, but Entra ID accounts are keyed in by hand from an emailed list — so people start on day two, seasonal contracts pile up, and CPR numbers occasionally end up copied into fields where they don’t belong.

Connect Lessor to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change at the source and acts on it automatically: new hires have their account, Office licence and group access ready on their registered start date, a move to another afdeling swaps the right groups the same day, Danish names resolve to clean logins, and leavers are disabled on their end date with a 30-day soft-delete grace window.

“Accounts used to lag a day or two behind the start date, and we were nervous about CPR numbers ending up in the wrong place. Now an account is simply ready on the start date, the login is always clean, and we can show exactly which Lessor change created every bit of access.” — Head of IT, wholesale distributor

The outcome this setup is designed for: onboarding drops from days to zero touch, CPR never leaves the HR source, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.

More than a connector

A standalone Lessor to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.

Schedule a demo

Installation manual

Installation manual

Connect Lessor to Microsoft Entra ID

Connect Lessor to Microsoft Entra ID

Installation guide

Follow these steps to connect Lessor to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.

1. Create your account

Go to platform.joinly.app and create your account.

Note: charges may apply for using the platform after the trial period ends.


Joinly account creation screen at platform.joinly.app


Sign up at platform.joinly.app to get started.

2. Connect your Microsoft account

Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.


Joinly identity provider setup screen for connecting a Microsoft Entra tenant


Connect your Microsoft tenant and pick your scopes.

3. Import your existing accounts from Entra ID

Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.

4. Find the Lessor integration in the Joinly marketplace

Open the Joinly marketplace and search for the Lessor integration.

Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.


Joinly marketplace showing available HR integrations


Search the marketplace for the Lessor integration.

5. Follow the installation wizard

You may be redirected to integrations.joinly.app. Create an account there and enter your Lessor connection details: the Emply People API endpoint (api.emply.com) and the API key you generate in the Emply platform under API. We only ask for the information needed to establish a successful connection with Lessor. All data is encrypted and stored securely.


Joinly installation wizard for entering Lessor connection details


Enter your Lessor / Emply People API endpoint and API key in the wizard.

6. Configure your field mapping

Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Lessor fields.

Frequently asked questions

  • How do I map the manager? Reference the manager’s employee identifier in the mapping and Joinly resolves the link to the right manager automatically.

  • How do I keep the CPR-nummer out of the directory? Map CPR only as an internal matching key; never reference it in the UPN or sAMAccountName template.

  • How do I handle Danish characters and prevent duplicate usernames? Use the generateUniqueUsername helper with a transliteration step, which falls back to the next pattern when the first one is already taken:
    {{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}


Joinly field mapping screen for Lessor attributes using Liquid templates


Map Lessor fields to Entra ID attributes with Liquid templates.

7. Configure the scheduled import

At platform.joinly.app/settings/import-configs, configure how often the import from Lessor should run.

8. Configure your workflows

Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Lessor flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the end date (for example 30 days) to retire accounts safely.


Joinly workflow editor creating an employee onboarding workflow


Create a trigger-based onboarding workflow.


Adding the create or update employee in Entra action to a workflow


Add the create/update action, then set your matching strategy and field mapping.


Adding the Entra soft delete action to remove accounts on employee leave


Add the Entra soft delete action to retire accounts safely.

## AD on-premise support

Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Lessor to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.

Frequently asked questions

Does the Lessor to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Lessor reach Entra ID quickly without waiting for a nightly batch.

Where does Joinly read Lessor data from?
From your Lessor employee master data in Emply People, the Lessor / Paychex Europe HR core, over its API (api.emply.com) using an API key you generate in the platform. LessorLøn and Lessor5 remain your Danish payroll engine; Joinly uses the HR record for identity.

How does Joinly handle the CPR-nummer and Danish characters?
The CPR-nummer is treated as sensitive data and kept inside Lessor as a matching key only — it never appears in a UPN or username. Names with æ, ø and å are transliterated and de-duplicated so every login is valid and unique.

Which attributes sync from Lessor to Entra ID?
Name, email / UPN, department (afdeling), job title (stilling), manager, and start and end date. Additional HR fields can be mapped via Liquid templates.

Is there a native Entra provisioning app for Lessor?
No. There is no first-party Entra inbound provisioning app for Lessor or Emply People, so the alternative is manual work or a generic middleware bridge. Joinly adds the role-to-group mapping, Danish naming rules and CPR handling that plain attribute sync leaves out.

Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Lessor to Active Directory guide.

Request installation support