When someone joins, moves or leaves in Liantis, you want that change reflected in Microsoft Entra ID without anyone re-keying it by hand. To connect Liantis to Microsoft Entra ID, Joinly reads each change in your My Liantis personnel file at the source and applies it automatically to the right account — creating, updating and disabling users to match. Liantis stays your social-secretariat source of truth for payroll and the Dimona; Joinly is the engine that turns that record into accurate, traceable access.
Key takeaways
Your Liantis personnel file stays the source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically.
Liantis is a payroll and social-secretariat system, not an identity source, so Joinly derives the org signal from job, joint committee (paritair comité) and cost data and maps it to the right Entra ID groups and licences.
Joinly keys account creation to the effective employment start date behind the Dimona declaration, so access is ready on the real first working day and not the moment the record is created.
The Belgian national number (rijksregisternummer) is treated as sensitive and never used as a login attribute — the UPN is built from name rules instead.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | Liantis (My Liantis personnel file, sociaal secretariaat) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Liantis personnel file (HRIS connector) → Joinly → Entra ID |
Supported events | Joiner, mover, leaver (incl. contract changes and rehire) |
Synced attributes | Name, email / UPN, job / function, department, joint committee, employee number, manager, start and end date |
Real-time or batch | Frequent scheduled sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Liantis to Microsoft Entra ID?
Joinly reads each change in your Liantis personnel file and applies it to the matching Entra ID account automatically. Liantis holds the authoritative employment record — the contract, the joint committee, the start and end date behind the Dimona — so it is the starting point for every identity action.
Joiner. HR records the new hire in Liantis and the Dimona is declared. Joinly reads the new employment record — name, job / function, joint committee, employee number and effective start date — and determines the role. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups, timed to the effective start date rather than the moment the record was entered.
Mover. When someone changes job, department or contract in Liantis, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual job.
Leaver. When Liantis records the end of the employment (the leaver Dimona / contract end), Joinly disables the Entra ID account automatically on the termination date. No orphaned accounts stay active after someone has left, and licences are freed up.
Example: A Belgian retail chain runs its payroll through Liantis and hires a store assistant with a start date next Monday. Joinly reads the employment record, waits until the effective start date, creates the Entra ID account, assigns a Microsoft 365 licence and adds the assistant to the Retail-StoreStaff group — while the rijksregisternummer stays in the HR record and never touches the login name.
What manual user management costs
Without automation, every account starts as an export from My Liantis or a message from the payroll administrator that IT re-keys into Entra ID by hand. Because Liantis is a social-secretariat and payroll system rather than an identity provider, there is no native connector that decides access for you — so the part that actually assigns groups and licences falls to people.
Onboarding delays. New joiners wait for accounts, licences and group access while a request sits in a queue, losing productive days in their first week — often the busiest, in retail and services.
Permissions that don’t keep up (privilege creep). When movers change job or store, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused Microsoft 365 licences keep costing money after the contract has ended in Liantis.
Joinly vs. a manual Liantis export
Liantis has no native identity-provisioning connector for Entra ID, so the realistic alternative is a CSV/Excel export from My Liantis re-keyed by hand, or a generic unified-API connector wired up with custom scripts. Here’s how that compares to Joinly.
Joinly | Manual export / generic connector | |
|---|---|---|
Source | Reads the Liantis personnel file directly | CSV/Excel export or a raw HRIS feed |
Role-to-group mapping | Built in, rule-based on job / joint committee | Manual; decided by whoever processes the export |
Future / start-date hires | Times account creation to the effective start date | Provisioned whenever the export is processed |
National number handling | Rijksregisternummer kept out of the login by design | Depends on manual discipline |
Licence assignment | Driven by role / attributes | Manual or group-based only |
On-premise AD | Yes, own agent plus the native Microsoft agent | Separate manual process |
Audit trail | Per-action logging tied to the HR source | None beyond the spreadsheet |
Watch-outs when connecting Liantis to Microsoft Entra ID
A few Liantis-specific details decide whether this connection stays reliable.
Liantis is payroll-first, not an identity source. The personnel file is structured for the sociaal secretariaat — contract, joint committee, seniority — not for IT access. Joinly derives the role from job, paritair comité and cost data and builds explicit mapping rules to Entra ID groups and licences, so access follows the record rather than a manual decision.
Start date behind the Dimona. The employment record and its official start are tied to the Dimona declaration, and the record can exist before the person’s real first working day. Joinly keys account creation to the effective employment start date, so access is ready on the right day and not before.
The national number is sensitive. The rijksregisternummer (INSZ/NISS) uniquely identifies a person in Liantis but must never become a login attribute. Joinly uses it only for matching where appropriate and builds the UPN from name rules instead.
UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, site code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Data arrives via export or connector, not a live event stream. Liantis exposes the personnel file through the portal and available connectors rather than a rich real-time API. Joinly runs a frequent scheduled import and applies your mapping on top, so changes flow through reliably without assuming a webhook feed Liantis doesn’t publish.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Liantis change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a Belgian retail chain with around 1,800 employees across 90 stores, running its payroll through Liantis while IT still creates every account by hand. The store managers hire constantly — students, seasonal staff, replacements — and each new name arrives as an export from My Liantis or a note from the payroll administrator that someone re-keys into Entra ID. New joiners routinely wait until their second or third shift for a working login, and when a contract ends in Liantis the Microsoft 365 account often stays active for weeks.
Connect Liantis to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each change in the Liantis personnel file at the source and acts on it automatically: new hires have their account, licence and group access ready on their effective start date, job or store changes swap the right groups the same day, and leavers are disabled on the contract end date with a 30-day soft-delete grace window — with the rijksregisternummer never leaving the HR record.
“We were re-typing every new starter from a Liantis export, and losing track of leavers. Now an account is simply ready on the first shift and gone when the contract ends, and we can show exactly which Liantis change created it.” — Head of IT, retail chain
The outcome this setup is designed for: onboarding drops from days to zero touch, leaver accounts and licences are cleaned up on time, and the team has a complete, source-backed audit trail for its next NIS2 assessment.
More than a connector
A standalone Liantis to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Liantis to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the Liantis integration in the Joinly marketplace
Open the Joinly marketplace and search for the Liantis integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Liantis integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Liantis connection details so Joinly can read your personnel file. We only ask for the information needed to establish a successful connection with Liantis. All data is encrypted and stored securely.

Enter your Liantis connection details in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Liantis fields such as job / function, joint committee and employee number.
Frequently asked questions
How do I map the manager? Reference the manager’s employee number in the mapping and Joinly resolves the link to the right manager automatically.
How do I keep the national number out of the login? Use name-based fields for the UPN and sAMAccountName; the rijksregisternummer is used only for matching, never as a login attribute.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map Liantis fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Liantis should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in the Liantis personnel file flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the termination date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Liantis to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Liantis to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in your Liantis personnel file reach Entra ID quickly without waiting for a nightly batch or a manual export.
Does Liantis have a native connector to Entra ID?
No. Liantis is a social secretariat and payroll system, not an identity provider, so there is no native provisioning connector. Joinly reads the personnel file and does the account creation, role-to-group mapping and offboarding that would otherwise be manual.
How does Joinly handle the Dimona start date?
Joinly keys account creation to the effective employment start date behind the Dimona declaration, so access is ready on the person’s real first working day rather than the moment the record was entered.
What happens to the Belgian national number (rijksregisternummer)?
It is treated as sensitive. Joinly uses it only for matching where appropriate and never as a login attribute — the UPN and username are built from name rules instead.
Which attributes sync from Liantis to Entra ID?
Name, email / UPN, job / function, department, joint committee, employee number, manager, and start and end date. Additional fields available in your Liantis personnel file can be mapped via Liquid templates.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Liantis to Active Directory guide.


