When someone joins, moves or leaves in Oracle HCM Cloud, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Oracle HCM Cloud to Microsoft Entra ID, Joinly reads each HR change in Oracle Fusion Cloud HCM at the source — through the Fusion HCM REST API — and applies it automatically to the right account. Oracle HCM stays your source of truth; Joinly is the engine that keeps every action accurate and traceable.
Key takeaways
Oracle Fusion Cloud HCM stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically.
Joinly maps Oracle HCM structures — legal entity, business unit, department, job, position and grade — to the right Entra ID groups and licences, work no native Entra app does for Oracle HCM out of the box.
Joinly reads date-effective records, so future-dated hires are provisioned exactly on their hire date and not the moment HR enters the assignment.
Multiple concurrent assignments under one or more work relationships are resolved correctly, so the primary assignment drives the UPN — the part custom OIC/SCIM builds usually get wrong.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | Oracle HCM Cloud (Oracle Fusion Cloud HCM) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Oracle Fusion HCM REST API → Entra ID |
Supported events | Joiner, mover, leaver (incl. rehire, global transfer, concurrent assignments) |
Synced attributes | Name, email / UPN, department, job, position, manager, grade, legal entity, business unit, hire and termination date |
Authentication | OAuth 2.0 over HTTPS to the Fusion HCM REST endpoint |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Oracle HCM Cloud to Microsoft Entra ID?
Joinly reads each HR change in Oracle Fusion Cloud HCM through the REST API and applies it to the matching Entra ID account automatically. Oracle HCM holds the authoritative worker and assignment record, so it is the starting point for each identity action.
Joiner. HR completes the hire in Oracle HCM. Joinly reads the new worker, work relationship and assignment and determines the role from attributes like department, job, position and grade. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the date-effective hire date.
Mover. When someone changes position, department or legal entity in Oracle HCM, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new assignment is revoked, so permissions stay aligned with the actual job.
Leaver. On the termination date recorded against the work relationship in Oracle HCM, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and concurrent assignments are taken into account so access is only removed when the last active assignment ends.
Example: An international bank hires a credit risk analyst in Oracle HCM with a hire date next Monday, in its Frankfurt legal entity. Joinly reads the date-effective record, waits until the hire date, creates the Entra ID account, assigns an Office E3 licence and adds the analyst to the DE-Risk group. When that analyst later picks up a second, concurrent assignment in the treasury business unit, Joinly keeps the primary assignment as the driver of the UPN and adds the extra group without breaking sign-in.
What manual user management costs
Without automation, every account starts as an Oracle HCM ticket or a line in a spreadsheet that IT works through by hand. There is no first-party Entra inbound app for Oracle HCM, so most teams build a custom pipeline — an Oracle Integration Cloud (OIC) adapter, or CSV / ATOM-feed-to-SCIM transformation scripts — that moves attributes across but maps roles to groups by hand and stumbles on date effectivity and multiple assignments, so the part that actually decides access still falls to people.
Onboarding delays. New joiners wait for accounts, licences and group access while a ticket sits in a queue, losing productive days in their first week.
Permissions that don’t keep up (privilege creep). When movers change position or legal entity, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — and with concurrent assignments it is easy to disable an account while another assignment is still active.
Joinly vs. a custom OIC / SCIM build for Oracle HCM
There is no first-party Entra inbound provisioning app for Oracle HCM, so the alternative is a custom OIC adapter or a CSV/ATOM-to-SCIM transformation pipeline. That moves data, but it stops short of the part that actually decides access. Here’s how the two compare for an Oracle Fusion HCM-driven setup.
Joinly | Custom OIC / ATOM-to-SCIM build | |
|---|---|---|
Source | Reads the Fusion HCM REST API directly | OIC adapter or CSV/ATOM export, then SCIM transform |
Role-to-group mapping | Built in, rule-based on business unit, job and position | Hand-coded in the transformation scripts |
Date-effective / future hires | Times account creation to the hire date | Needs custom effective-date handling in the pipeline |
Concurrent assignments | Resolves the primary assignment for the UPN | Easy to sync the wrong or terminated assignment |
Licence assignment | Driven by role / attributes | Manual or group-based only |
On-premise AD | Yes, own agent plus the native Microsoft agent | Extra SCIM-to-AD plumbing to build and maintain |
Audit trail | Per-action logging tied to the HR source | Whatever you log in the pipeline yourself |
Watch-outs when connecting Oracle HCM Cloud to Microsoft Entra ID
A few Oracle HCM-specific details decide whether this connection stays reliable at scale.
Date-effective future hires. Oracle HCM stores a hire as a date-effective record well before the first working day, and provisioning too early or too late both cause problems. Joinly reads the effective hire date and times account creation to it, so access is ready on the right day and not before.
Multiple concurrent assignments. A person can hold more than one active assignment, under one or more work relationships. A naive rule can sync the wrong — or a terminated — assignment to Entra ID and break sign-in. Joinly applies explicit rules to pick the primary assignment as the driver of the UPN, while still reflecting the extra access.
Position model vs job model. Oracle HCM can be deployed on a position model or a job model, and the two expose access-defining attributes differently. Joinly maps from whichever your tenant uses — position, job and grade — to the correct Entra groups and licences, so role drives access rather than manual assignment.
UPN format with duplicate names. When two workers share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, legal-entity code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Custom flexfields. Oracle HCM descriptive and extensible flexfields aren’t all exposed by default. Joinly maps the custom fields you need via Liquid templates, so attributes like a local employee number or assignment DFF land in the right place.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Oracle HCM change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture an international bank with around 8,000 employees across four legal entities, running Oracle Fusion Cloud HCM as its HR core while its identity provisioning never quite keeps up. A custom OIC-to-SCIM pipeline handles the simple cases, yet secondments, internal transfers between entities and a steady stream of concurrent assignments keep breaking it — analysts with a second assignment end up with the wrong one synced to Entra ID, and future-dated hires are provisioned the moment HR saves the record rather than on their actual hire date.
Connect Oracle HCM Cloud to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change in Oracle HCM at the source and acts on it automatically: new hires have their account, Office licence and group access ready on their date-effective hire date, transfers between legal entities swap the right groups the same day, concurrent assignments keep a single, stable UPN, and leavers are disabled on their termination date with a 30-day soft-delete grace window.
“Concurrent assignments used to be the thing that broke every sync. Now an account is simply ready on the hire date, a second assignment just adds access, and we can show the auditor exactly which Oracle HCM change created every bit of access.” — Head of IT, international bank
The outcome this setup is designed for: onboarding drops from days to zero touch, concurrent-assignment errors stop entirely, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone Oracle HCM to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Oracle HCM Cloud to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the Oracle HCM Cloud integration in the Joinly marketplace
Open the Joinly marketplace and search for the Oracle HCM Cloud integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Oracle HCM Cloud integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Oracle HCM connection details: your Fusion HCM REST API host (your Oracle Cloud pod URL), and the OAuth client credentials for the integration user. We only ask for the information needed to establish a successful connection with Oracle HCM. All data is encrypted and stored securely.

Enter your Oracle Fusion HCM REST host and OAuth credentials in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Oracle HCM fields.
Frequently asked questions
How do I map the manager? Reference the manager’s assignment in the mapping and Joinly resolves the link to the right manager automatically.
How do I handle concurrent assignments? Pick the primary assignment as the driver for the UPN; Joinly exposes the active assignments so you can choose the primary one.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map Oracle HCM fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Oracle HCM should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Oracle HCM flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the termination date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Oracle HCM Cloud to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Oracle HCM Cloud to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Oracle Fusion Cloud HCM reach Entra ID quickly without waiting for a nightly batch.
How does Joinly handle multiple concurrent assignments?
Joinly reads all active assignments for a person and applies your rules to pick the primary assignment as the driver for the UPN, so a second or secondment assignment adds access without creating a duplicate account or breaking sign-in.
How are future-dated hires handled?
Joinly reads the date-effective hire date on the Oracle HCM record and times account creation to it, so access is ready on the hire date rather than the moment HR saved the record.
Which attributes sync from Oracle HCM to Entra ID?
Name, email / UPN, department, job, position, manager, grade, legal entity, business unit, and hire and termination date. Custom flexfields can be mapped via Liquid templates.
Do I need to build a custom OIC or SCIM pipeline?
No. There is no first-party Entra inbound app for Oracle HCM, but Joinly reads the Fusion HCM REST API directly and takes over the provisioning, role-to-group mapping and concurrent-assignment handling a custom build does by hand or not at all.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Oracle HCM Cloud to Active Directory guide.


