When someone joins, moves or leaves in Rippling, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Rippling to Microsoft Entra ID, Joinly reads each HR change at the source — through the Rippling REST API — and applies it automatically to the right account in your tenant. Rippling stays your HR system of record; Entra ID stays your directory of record; Joinly is the engine that drives HR-sourced changes into Entra and keeps every action accurate and traceable.
Key takeaways
Rippling stays your HR source of truth, but Entra ID stays your directory of record — Joinly drives every joiner, mover and leaver from Rippling into Entra ID instead of standing up a second identity tower.
Joinly maps Rippling roles, departments, teams and work locations to your existing Entra ID groups and licences — into the groups your tenant already governs, not new ones Rippling decides to create.
Because Rippling itself wants to be the identity provider, Joinly is the right fit when your directory of record is Entra ID and Rippling is only your HR and payroll system.
Joinly works from the Rippling REST API rather than treating Rippling as a SCIM source (it has no inbound SCIM endpoint), so the sync is built for how Rippling actually exposes data.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | Rippling (HRIS) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Rippling REST API → Entra ID |
Supported events | Joiner, mover, leaver (incl. rehire, department transfer, role change) |
Synced attributes | Name, email / UPN, department, job title, manager, role, team, work location, start and end date |
Authentication | OAuth 2.0 / bearer token (Rippling API) |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Rippling to Microsoft Entra ID?
Joinly reads each HR change in Rippling through the REST API and applies it to the matching Entra ID account automatically. Rippling holds the authoritative employment record, so it is the starting point for each identity action — but the account itself lives and is governed in your Entra tenant.
Joiner. HR completes the hire in Rippling. Joinly reads the new employee, their department, role, team and work location, and determines the access profile from those attributes. It then creates the account in Entra ID, assigns the right licences and maps the person into your existing Entra groups — timed to the start date recorded in Rippling.
Mover. When someone changes role, department, team or work location in Rippling, Joinly updates their Entra group membership, permissions and licences to match. Access that no longer fits the new role is revoked, so permissions stay aligned with the actual job rather than accumulating.
Leaver. On the termination date recorded in Rippling, Joinly disables the Entra ID account automatically. No orphaned accounts are left active after someone has left, and licences are freed instead of quietly billing month after month.
Example: A software company runs Rippling for HR and payroll but treats Microsoft Entra ID as its directory of record. It hires a backend engineer in Rippling with a start date next Monday, in the Platform team. Joinly reads the record, waits until the start date, creates the Entra ID account, assigns a Microsoft 365 E3 licence and adds the engineer to the existing ENG-Platform and All-Engineering groups the tenant already governs. When that engineer later moves to the Security team, Joinly swaps the group membership the same day rather than letting the old Platform access linger.
What manual user management costs
Without automation, every account starts as a Rippling notification or a line in a spreadsheet that IT works through by hand. Rippling’s own app provisioning and the Microsoft Entra API-driven path can move attributes across, but Rippling is built to be your identity provider — so when Entra ID is your directory of record, the role-to-group mapping into the groups you already govern still falls to people.
Onboarding delays. New joiners wait for accounts, licences and group access while a request sits in a queue, losing productive days in their first week.
Permissions that don’t keep up (privilege creep). When movers change role or department in Rippling, old Entra access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused Microsoft 365 licences keep costing money long after someone has left.
Joinly vs. Rippling’s own provisioning
Rippling can provision apps itself, and there’s a Rippling-built path into Entra ID. But Rippling is designed to be the identity provider, and that’s exactly the question: if your directory of record is Entra ID, do you want Rippling driving identity, or HR data flowing into the directory you already govern? Here’s how the two compare.
Joinly | Rippling native provisioning | |
|---|---|---|
Directory of record | Entra ID stays the directory; Joinly feeds it | Rippling positions itself as the identity provider |
Source | Reads the Rippling REST API directly | Rippling provisions from its own data |
Role-to-group mapping | Maps roles/departments to your existing Entra groups | Limited; tends to manage its own app groups |
Governance & audit | Per-action logging tied to the HR source, in your tenant | Audit lives inside Rippling, not your directory |
Licence assignment | Driven by role / attributes in Entra | App-based, managed in Rippling |
On-premise AD | Yes, own agent plus the native Microsoft agent | Via the Entra provisioning agent; limited mapping |
Fit | Entra/AD is the directory, Rippling is HR/payroll | Rippling is the identity hub for everything |
Watch-outs when connecting Rippling to Microsoft Entra ID
A few Rippling-specific details decide whether this connection stays reliable and stays under your governance.
Rippling wants to be the IdP. Rippling is built to be the identity provider and to provision apps itself. If your directory of record is Entra ID, you don’t want a second identity tower — Joinly keeps Entra as the directory and uses Rippling purely as the HR source, so identity stays where you govern it.
Mapping roles to your existing Entra groups. Rippling roles, departments, teams and work locations don’t translate one-to-one to Entra ID groups. Joinly builds explicit rules from those structures into the groups your tenant already owns, so HR data lands in your governed groups rather than new ones.
No inbound SCIM endpoint. Rippling is an outbound IdP, not a downstream SCIM app, so you can’t treat it like a normal SCIM source. Joinly reads the Rippling REST API directly, which is how Rippling actually exposes employee, department and role data.
UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, location code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Custom Rippling fields. Custom Rippling attributes and a local employee number aren’t all surfaced the same way. Joinly maps the custom fields you need via Liquid templates, so the attributes you rely on land in the right place in Entra.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Rippling change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request — and the trail lives in the directory you govern, not inside Rippling. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a software company with around 900 employees that runs Rippling for HR and payroll but standardised long ago on Microsoft Entra ID as its directory of record. Rippling keeps trying to be the identity hub, and the native path provisions some apps from Rippling’s side — yet the Entra groups that actually gate the codebase, the cloud accounts and the SaaS tools are governed in the tenant, so every new engineer still needs someone to map their role into the right groups by hand.
Connect Rippling to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change in Rippling at the source and acts on it in your tenant: new hires have their account, Microsoft 365 licence and existing-group access ready on their start date, team moves swap the right Entra groups the same day, and leavers are disabled on their termination date with a soft-delete grace window — all while Entra stays the directory of record.
“We didn’t want Rippling to become a second identity system. Now Rippling stays our HR source, Entra stays our directory, and every engineer lands in exactly the groups we already govern — on their start date, with a trail we can show the auditor.” — Head of IT, software company
The outcome this setup is designed for: onboarding drops from days to zero touch, Entra stays the single directory of record, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone Rippling to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Rippling to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the Rippling integration in the Joinly marketplace
Open the Joinly marketplace and search for the Rippling integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Rippling integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Rippling connection details: authorise Joinly against the Rippling REST API and provide the OAuth credentials or API token with read access to employees, departments, roles and work locations. We only ask for the information needed to establish a successful connection with Rippling. All data is encrypted and stored securely.

Authorise Joinly against the Rippling API and enter your credentials in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Rippling fields.
Frequently asked questions
How do I map the manager? Reference the manager’s Rippling employee ID in the mapping and Joinly resolves the link to the right manager automatically.
How do I map roles to my existing Entra groups? Build rules from Rippling role, department, team and work location into the groups your tenant already governs.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map Rippling fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Rippling should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Rippling flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the termination date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Rippling to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Rippling to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Rippling reach Entra ID quickly without waiting for a nightly batch.
Rippling already provisions apps itself — why use Joinly?
Because Rippling is built to be the identity provider, while many organisations keep Microsoft Entra ID as their directory of record. Joinly drives HR-sourced joiner, mover and leaver from Rippling into Entra and your existing groups, so Rippling stays your HR source and Entra stays your directory, rather than running two identity systems.
How does Joinly map Rippling data to my existing Entra groups?
Joinly builds explicit rules from Rippling role, department, team and work location into the Entra groups your tenant already governs, so HR data drives membership of the groups you own rather than new ones.
Which attributes sync from Rippling to Entra ID?
Name, email / UPN, department, job title, manager, role, team, work location, and start and end date. Custom Rippling fields can be mapped via Liquid templates.
Does Joinly use Rippling’s SCIM endpoint?
No. Rippling is an outbound identity provider and doesn’t expose an inbound SCIM endpoint, so Joinly reads the Rippling REST API directly — which is how Rippling actually surfaces employee, department and role data.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Rippling to Active Directory guide.


