Connect Oracle PeopleSoft to Microsoft Entra ID

Connect Oracle PeopleSoft to Microsoft Entra ID

Connect Oracle PeopleSoft to Microsoft Entra ID

When someone joins, moves or leaves in Oracle PeopleSoft, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Oracle PeopleSoft to Microsoft Entra ID, Joinly reads each HR change in PeopleSoft HCM at the source — through the PeopleSoft Integration Broker’s web services — and applies it automatically to the right account. PeopleSoft stays your system of record; Joinly is the engine that keeps every action accurate and traceable.

Key takeaways

  • PeopleSoft HCM stays your system of record; Joinly applies every joiner, mover and leaver to Entra ID automatically.

  • Joinly reads Job Data through the PeopleSoft Integration Broker (REST/SOAP services and Component Interfaces), so you don’t need a Microsoft gallery app — because there isn’t one for PeopleSoft.

  • Joinly maps PeopleSoft structures — Business Unit, Department, Location, Company and Position — to the right Entra ID groups and licences, which a raw web-service feed can’t do on its own.

  • Joinly reads effective-dated rows (EFFDT / EFFSEQ), so future-dated hires are provisioned on their real start date and not the moment HR keys the Job Data row.

  • Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.

Oracle PeopleSoft

Joiner

Mover

Leaver

Microsoft Entra ID (formerly Azure AD)

Quick facts

Source system

Oracle PeopleSoft (PeopleSoft HCM 9.2)

Target system

Microsoft Entra ID (formerly Azure AD)

Connection method

PeopleSoft Integration Broker (REST/SOAP, Component Interfaces) → Entra ID

Supported events

Joiner, mover, leaver (incl. rehire, transfer, multiple Empl Records)

Synced attributes

Name, email / UPN, EMPLID, department, job title, manager, Business Unit, Company, Location, start and end date

Source key

EMPLID (mapped to a stable UPN / login)

Real-time or batch

Frequent sync, multiple times per day

Compliance

ISO 27001, NIS2-ready, GDPR (EU data centre)

How does Joinly sync Oracle PeopleSoft to Microsoft Entra ID?

Joinly reads each HR change in PeopleSoft HCM through the Integration Broker’s web services and applies it to the matching Entra ID account automatically. PeopleSoft holds the authoritative Job Data record, so it is the starting point for each identity action.

  1. Joiner. HR completes the hire in PeopleSoft with an Action of HIR on a new Job Data row. Joinly reads the person and their current (max-EFFDT/EFFSEQ) Job Data — Department, Business Unit, Location, Company and Position — determines the role, then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups, timed to the effective date on the row.

  2. Mover. When someone changes position, department, Business Unit or Company on a new effective-dated row, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual job rather than an old one.

  3. Leaver. On the termination row (Action TER) in PeopleSoft, Joinly disables the Entra ID account automatically on the effective date. No orphaned accounts are left active after someone leaves, and where a person holds more than one Empl Record, access is only removed when the last active employment ends.

Example: A university hires a lecturer in PeopleSoft with a HIR row effective next Monday, in the Faculty of Science Business Unit. Joinly reads the effective-dated row, waits until the start date, creates the Entra ID account, assigns an Office E3 licence and adds the lecturer to the SCI-Staff group. When that lecturer later picks up a second, concurrent appointment on a new Empl Record in another department, Joinly keeps one stable account and adds the extra group without breaking sign-in.

What manual user management costs

Without automation, every account starts as a PeopleSoft ticket or a PS Query export that IT works through by hand. A raw Integration Broker feed or a partner ECMA connector can move attributes across, but it maps roles to groups through hand-built rules and stumbles on effective dating and multiple Empl Records — so the part that actually decides access still falls to people.

  • Onboarding delays. New joiners wait for accounts, licences and group access while a ticket sits in a queue, losing productive days in their first week.

  • Permissions that don’t keep up (privilege creep). When movers change position, department or Business Unit, old access often stays attached, so people accumulate rights they no longer need.

  • Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — and with multiple Empl Records it is easy to disable an account while another appointment is still active.

Joinly vs. a custom PeopleSoft Integration Broker feed

There is no Microsoft Entra gallery app for PeopleSoft, so the native path is a custom Integration Broker service (or an Entra ECMA / IGA connector). That is a fine baseline for moving attributes, but it stops short of the part that actually decides access. Here’s how the two compare for a PeopleSoft HCM-driven setup.


Joinly

Custom Integration Broker / ECMA connector

Source

Reads PeopleSoft Job Data via Integration Broker

Custom-built service per integration

Role-to-group mapping

Built in, rule-based on Business Unit / Department / Position

Hand-coded; no role-to-group out of the box

Effective-dated / future hires

Reads the effective row and times creation to EFFDT

Must implement max-EFFDT / future-row logic yourself

Multiple Empl Records

Resolves which employment drives the account

Easy to sync the wrong or terminated Empl Record

Licence assignment

Driven by role / attributes

Manual or group-based only

On-premise AD

Yes, own agent plus the native Microsoft agent

Separate build; limited mapping

Audit trail

Per-action logging tied to the HR source

Whatever you build and log yourself

Watch-outs when connecting Oracle PeopleSoft to Microsoft Entra ID

A few PeopleSoft-specific details decide whether this connection stays reliable at scale.

  • Effective-dated future rows (EFFDT / EFFSEQ). PeopleSoft stores a hire or transfer as a future-dated Job Data row, and the current state is the max-EFFDT/EFFSEQ row as of today. Reading naively provisions too early or picks the wrong row. Joinly reads the effective row and times account creation to the EFFDT, so access is ready on the right day and not before.

  • Integration Broker setup. Data only flows once the Integration Broker is configured — gateway, nodes, and the service operations or Component Interfaces that expose Job Data. Joinly works with your existing services or the delivered CIs, so you connect to what PeopleSoft already publishes instead of building a bespoke feed from scratch.

  • EMPLID is the key, not the login. PeopleSoft identifies a person by EMPLID, which is not the Entra ID UPN. Joinly maps EMPLID to a stable, unique UPN and keeps that link across rehires and transfers, so a person is never duplicated and never loses their account on a job change.

  • Multiple Empl Records. A person can hold more than one job at once, each on its own Empl Record (EMPL_RCD, starting at 0). Joinly applies explicit rules to pick the driving employment for the account while still reflecting the extra access, so a second appointment adds groups rather than a second account.

  • Mapping PeopleSoft structures to Entra groups. Business Unit, Department, Location, Company and Position don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from those structures to the correct groups and licences, so role drives access rather than manual assignment.

Joinly handles each of these by default with custom mapping and transformation.

Always audit-ready

Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which PeopleSoft change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.

Example case

Picture a university with around 9,000 staff and a long-standing on-premise PeopleSoft HCM as its system of record, while its identity provisioning never quite keeps up. There is no gallery app to lean on, so a home-grown Integration Broker export feeds a nightly script — which handles the simple cases but breaks on the rest: future-dated academic appointments provision the moment HR keys the row rather than on the start date, and staff with a second Empl Record in another faculty end up with the wrong employment driving their account.

Connect Oracle PeopleSoft to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each Job Data change at the source and acts on it automatically: new hires have their account, Office licence and group access ready on the effective start date, transfers between Business Units swap the right groups the same day, a second appointment simply adds access on one stable account, and leavers are disabled on the termination row with a 30-day soft-delete grace window.

“We used to babysit a script that read PeopleSoft every night and still got future-dated hires and second appointments wrong. Now an account is simply ready on the start date, a second Empl Record just adds access, and we can show the auditor exactly which Job Data change created every bit of access.” — Head of IT, higher-education institution

The outcome this setup is designed for: onboarding drops from days to zero touch, effective-dating and multiple-appointment errors stop entirely, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.

More than a connector

A standalone Oracle PeopleSoft to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.

Schedule a demo

Installation manual

Installation manual

Connect Oracle PeopleSoft to Microsoft Entra ID

Connect Oracle PeopleSoft to Microsoft Entra ID

Installation guide

Follow these steps to connect Oracle PeopleSoft to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.

1. Create your account

Go to platform.joinly.app and create your account.

Note: charges may apply for using the platform after the trial period ends.


Joinly account creation screen at platform.joinly.app


Sign up at platform.joinly.app to get started.

2. Connect your Microsoft account

Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.


Joinly identity provider setup screen for connecting a Microsoft Entra tenant


Connect your Microsoft tenant and pick your scopes.

3. Import your existing accounts from Entra ID

Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.

4. Find the PeopleSoft integration in the Joinly marketplace

Open the Joinly marketplace and search for the Oracle PeopleSoft integration.

Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.


Joinly marketplace showing available HR integrations


Search the marketplace for the Oracle PeopleSoft integration.

5. Follow the installation wizard

You may be redirected to integrations.joinly.app. Create an account there and enter your PeopleSoft connection details: the Integration Broker gateway / service endpoint URL, the service operation or Component Interface to read, and the credentials for the integration user. We only ask for the information needed to establish a successful connection with PeopleSoft. All data is encrypted and stored securely.


Joinly installation wizard for entering Oracle PeopleSoft connection details


Enter your PeopleSoft Integration Broker endpoint and integration-user credentials in the wizard.

6. Configure your field mapping

Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from PeopleSoft fields.

Frequently asked questions

  • How do I map the manager? Reference the manager’s EMPLID in the mapping and Joinly resolves the link to the right manager automatically.

  • How do I handle multiple Empl Records? Pick the driving Empl Record for the account; Joinly exposes the active employments so you can choose the primary one.

  • How do I prevent duplicate usernames? Use the generateUniqueUsername helper, which falls back to the next pattern when the first one is already taken:
    {{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}


Joinly field mapping screen for PeopleSoft attributes using Liquid templates


Map PeopleSoft fields to Entra ID attributes with Liquid templates.

7. Configure the scheduled import

At platform.joinly.app/settings/import-configs, configure how often the import from PeopleSoft should run.

8. Configure your workflows

Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in PeopleSoft Job Data flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the termination date (for example 30 days) to retire accounts safely.


Joinly workflow editor creating an employee onboarding workflow


Create a trigger-based onboarding workflow.


Adding the create or update employee in Entra action to a workflow


Add the create/update action, then set your matching strategy and field mapping.


Adding the Entra soft delete action to remove accounts on employee leave


Add the Entra soft delete action to retire accounts safely.

## AD on-premise support

Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Oracle PeopleSoft to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.

Frequently asked questions

Does the PeopleSoft to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in PeopleSoft Job Data reach Entra ID quickly without waiting for a nightly batch.

Is there a Microsoft gallery app for PeopleSoft provisioning?
No. Microsoft’s Entra gallery has an Oracle HCM app, but that targets Oracle HCM Cloud (Fusion), not on-premise PeopleSoft. For PeopleSoft you need a custom Integration Broker service or a connector — which is exactly what Joinly provides, with role-to-group mapping and effective-dating built in.

How are future-dated hires and effective-dated rows handled?
Joinly reads the effective row on the Job Data record (max EFFDT / EFFSEQ) and times account creation to the EFFDT, so access is ready on the start date rather than the moment HR keyed the row.

How does Joinly handle someone with more than one job (Empl Record)?
Joinly reads all active Empl Records for a person and applies your rules to pick the driving employment for the account, so a second or additional appointment adds access without creating a duplicate account or breaking sign-in.

Which attributes sync from PeopleSoft to Entra ID?
Name, email / UPN, EMPLID, department, job title, manager, Business Unit, Company, Location, and start and end date. Additional PeopleSoft fields can be mapped via Liquid templates.

Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the PeopleSoft to Active Directory guide.

Request installation support