Connect Partena Professional to Microsoft Entra ID

Connect Partena Professional to Microsoft Entra ID

Connect Partena Professional to Microsoft Entra ID

When someone joins, moves or leaves in Partena Professional, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Partena Professional to Microsoft Entra ID, Joinly reads each HR change from your Partena payroll administration — through the data channel your ProSalary or ExpertSalary setup exposes — and applies it automatically to the right account. Partena stays your source of truth for the employment record; Joinly is the engine that keeps every account accurate and traceable.

Key takeaways

  • Your Partena Professional payroll administration stays the source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically.

  • Joinly maps Partena’s payroll structure — department, function, cost centre, joint committee (paritair comité) and worker number (matricule) — to the right Entra ID groups and licences, which no Partena partner connector does.

  • Because Partena is a social secretariat, the data channel and cadence depend on your contract and platform; Joinly is built around whatever ProSalary or ExpertSalary actually exposes, rather than assuming a fixed API.

  • Bilingual (NL/FR) names and org labels are transliterated cleanly into a unique, predictable UPN, so accented or mixed-language values never break sign-in.

  • Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.

Partena Professional

Joiner

Mover

Leaver

Microsoft Entra ID (formerly Azure AD)

Quick facts

Source system

Partena Professional (ProSalary / ExpertSalary payroll administration)

Target system

Microsoft Entra ID (formerly Azure AD)

Connection method

Partena payroll data channel (partner API or scheduled export) → Joinly → Entra ID

Supported events

Joiner, mover, leaver (incl. rehire and contract changes)

Synced attributes

Name, email / UPN, department, function, manager, cost centre, worker number, start and end date

Authentication

Per your Partena setup — partner API credentials or a secured export channel

Real-time or batch

Frequent sync, multiple times per day (cadence depends on the Partena channel)

Compliance

ISO 27001, NIS2-ready, GDPR (EU data centre)

How does Joinly sync Partena Professional to Microsoft Entra ID?

Joinly reads each HR change from your Partena payroll administration and applies it to the matching Entra ID account automatically. Partena holds the authoritative employment record — contract, function, joint committee and start and end dates — so it is the starting point for each identity action.

  1. Joiner. The employee is set up in Partena and declared to the NSSO through Dimona. Joinly reads the new employment record, determines the role from attributes like department, function and cost centre, then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the contractual start date.

  2. Mover. When someone changes function, department or cost centre in Partena, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual job.

  3. Leaver. When the departure is recorded in Partena — the contract end and the Dimona out declaration — Joinly disables the Entra ID account automatically on the end date. No orphaned accounts stay active after someone has left, and no unused licences keep billing.

Example: A Belgian non-profit runs its payroll through Partena’s ProSalary and hires a project coordinator with a start date on the first of next month. Joinly reads the new employment record, waits until the start date, creates the Entra ID account, assigns a Microsoft 365 licence and adds the coordinator to the Programmes group. When the coordinator later moves from Programmes to Fundraising, Joinly swaps the groups the same day the change lands in Partena.

What manual user management costs

Without automation, every account starts as an email from the Partena payroll consultant or a line in a spreadsheet that IT works through by hand. Partena’s own platform integrations can import employee data into another HR tool, but they don’t create Entra ID accounts, map functions to groups or disable leavers — so the part that actually decides access still falls to people.

  • Onboarding delays. New joiners wait for accounts, licences and group access while a request sits in a queue, losing productive days in their first week.

  • Permissions that don’t keep up (privilege creep). When movers change function or department, old access often stays attached, so people accumulate rights they no longer need.

  • Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused Microsoft 365 licences keep costing money after someone’s contract has ended.

Joinly vs. a Partena partner connector or manual export

Partena’s partner integrations import HR data into another HR tool, and a manual CSV/SFTP export gets data out — but neither provisions identities. Here’s how Joinly compares with the do-it-yourself alternatives for a Partena-driven setup.


Joinly

Partner connector / manual export

Source

Reads your Partena payroll channel directly

Imports into another HR tool, or a hand-built export

Provisions to Entra ID

Creates, updates and disables accounts

No — moves data between HR systems only

Role-to-group mapping

Built in, rule-based on function and cost centre

Not available

Bilingual NL/FR values

Transliterated into clean UPN / display name

Passed through as-is

Licence assignment

Driven by role / attributes

Manual

On-premise AD

Yes, own agent plus the native Microsoft agent

Not available

Audit trail

Per-action logging tied to the HR source

None

Watch-outs when connecting Partena Professional to Microsoft Entra ID

A few Partena-specific details decide whether this connection stays reliable at scale.

  • The data channel depends on your Partena setup. As a social secretariat, Partena surfaces employee data through ProSalary or ExpertSalary and its partner API, or through an export you arrange — the exact channel and cadence vary by contract. Joinly is built to read whichever channel your setup exposes, so provisioning doesn’t hinge on a single documented API.

  • Payroll structure isn’t IT identity. Partena records are shaped for Dimona, DmfA and gross-to-net calculation, keyed on the worker number (matricule) and joint committee rather than on directory groups. Joinly builds explicit rules from department, function and cost centre to the correct Entra ID groups and licences, so role drives access.

  • Bilingual names and diacritics. Values arrive in Dutch and French, often with accented characters. A naive rule produces inconsistent or colliding usernames. Joinly transliterates and applies custom transformation rules so every UPN is unique, clean and predictable from day one.

  • Contract end vs. actual last day. The Dimona out and the contract end date drive offboarding. Joinly keys account disablement to the recorded end date, with an optional grace window, so access ends on the right day and not before or long after.

Joinly handles each of these by default with custom mapping and transformation.

Always audit-ready

Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Partena Professional change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.

Example case

Picture a Belgian non-profit in the social sector with around 900 employees across a head office and a dozen local branches, running its payroll through Partena’s ProSalary while its IT team still creates every account by hand. New social workers and support staff start as an email from the payroll consultant, and IT keys them into Entra ID one at a time — choosing groups, assigning a Microsoft 365 licence, matching Dutch and French names to a username. With short project contracts and frequent internal moves the queue never empties, and joiners often wait until day two or three for access.

Connect Partena Professional to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each change in the Partena payroll administration at the source and acts on it automatically: new hires have their account, licence and group access ready on their start date, moves between programmes swap the right groups the same day, bilingual names resolve to one clean UPN, and leavers are disabled on their contract end date with a 30-day soft-delete grace window.

“Onboarding used to be a stack of emails from our payroll consultant that we typed into Entra ID by hand. Now an account is simply ready on the start date, moves happen the same day, and we can show the auditor exactly which Partena change created every bit of access.” — Head of IT, social-sector non-profit

The outcome this setup is designed for: onboarding drops from days to zero touch, privilege creep from old roles is eliminated, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.

More than a connector

A standalone Partena Professional to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.

Schedule a demo

Installation manual

Installation manual

Connect Partena Professional to Microsoft Entra ID

Connect Partena Professional to Microsoft Entra ID

Installation guide

Follow these steps to connect Partena Professional to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.

1. Create your account

Go to platform.joinly.app and create your account.

Note: charges may apply for using the platform after the trial period ends.


Joinly account creation screen at platform.joinly.app


Sign up at platform.joinly.app to get started.

2. Connect your Microsoft account

Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.


Joinly identity provider setup screen for connecting a Microsoft Entra tenant


Connect your Microsoft tenant and pick your scopes.

3. Import your existing accounts from Entra ID

Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.

4. Find the Partena Professional integration in the Joinly marketplace

Open the Joinly marketplace and search for the Partena Professional integration.

Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.


Joinly marketplace showing available HR integrations


Search the marketplace for the Partena Professional integration.

5. Follow the installation wizard

You may be redirected to integrations.joinly.app. Create an account there and enter your Partena connection details for the channel your setup uses — partner API credentials or the secured export you’ve arranged with Partena for ProSalary or ExpertSalary. Not sure which channel applies to your contract? Contact support@koppelhet.nl and we’ll help you set it up. We only ask for the information needed to establish a successful connection. All data is encrypted and stored securely.


Joinly installation wizard for entering Partena Professional connection details


Enter your Partena connection details in the wizard.

6. Configure your field mapping

Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Partena fields — including transliterating bilingual NL/FR names.

Frequently asked questions

  • How do I map the manager? Reference the manager’s worker number in the mapping and Joinly resolves the link to the right manager automatically.

  • How do I handle accented, bilingual names? Use the transliteration helpers so Dutch and French names resolve to a clean, ASCII UPN and sAMAccountName.

  • How do I prevent duplicate usernames? Use the generateUniqueUsername helper, which falls back to the next pattern when the first one is already taken:
    {{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}


Joinly field mapping screen for Partena Professional attributes using Liquid templates


Map Partena fields to Entra ID attributes with Liquid templates.

7. Configure the scheduled import

At platform.joinly.app/settings/import-configs, configure how often the import from Partena should run.

8. Configure your workflows

Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Partena flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the contract end date (for example 30 days) to retire accounts safely.


Joinly workflow editor creating an employee onboarding workflow


Create a trigger-based onboarding workflow.


Adding the create or update employee in Entra action to a workflow


Add the create/update action, then set your matching strategy and field mapping.


Adding the Entra soft delete action to remove accounts on employee leave


Add the Entra soft delete action to retire accounts safely.

## AD on-premise support

Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Partena Professional to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.

Frequently asked questions

Does the Partena Professional to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Partena reach Entra ID quickly without waiting for a nightly batch. The exact cadence depends on the data channel your ProSalary or ExpertSalary setup exposes.

How does Joinly read data out of Partena Professional?
Partena is a social secretariat, so employee data is surfaced through its ProSalary or ExpertSalary platform and partner API, or through a secured export you arrange. Joinly reads whichever channel your contract exposes; if you’re unsure which applies, our team helps you set it up.

How are bilingual Dutch and French names handled?
Joinly transliterates accented and mixed-language values into a clean, unique UPN and sAMAccountName using Liquid templates, so names never break sign-in or produce collisions.

Which attributes sync from Partena to Entra ID?
Name, email / UPN, department, function, manager, cost centre, worker number, and start and end date. Additional fields your Partena setup exposes can be mapped via Liquid templates.

Do I need a special Partena API for this?
You need whatever data channel your Partena contract provides — a partner API connection or a secured export. Joinly is built to work with either, so you don’t have to force a specific integration that your setup doesn’t offer.

Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Partena Professional to Active Directory guide.

Request installation support