When someone joins, moves or leaves in Sage People, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Sage People to Microsoft Entra ID, Joinly reads each HR change at the source — through the Salesforce Platform API that Sage People is built on, authenticating with OAuth against your Salesforce org — and applies it automatically to the right account. Sage People stays your source of truth; Joinly is the engine that keeps every action accurate and traceable.
Key takeaways
Sage People stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically from the Team Member and Employment Record data.
Because Sage People is built on Salesforce, Joinly connects through a Salesforce Connected App with OAuth 2.0 and reads the HR objects directly — not the licensed Salesforce login.
Joinly maps Sage People structure — HR Department, Team, Business Unit and manager — to the right Entra ID groups and licences, something the native Salesforce provisioning app doesn’t do.
Joinly drives provisioning from the Sage People Team Member, so the person’s HR record decides access rather than whether they hold a Salesforce User seat.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | Sage People (Team Member records on Salesforce) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Salesforce Platform API (OAuth Connected App) → Entra ID |
Supported events | Joiner, mover, leaver (incl. rehire and internal transfers) |
Synced attributes | Name, email / UPN, department, job title, manager, HR Department, Business Unit, start and end date |
Authentication | Salesforce OAuth 2.0 via a Connected App (bearer token, API-only integration user) |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Sage People to Microsoft Entra ID?
Joinly reads each HR change in your Sage People org through the Salesforce Platform API and applies it to the matching Entra ID account automatically. The Sage People Team Member and its Employment Record hold the authoritative employment details, so they are the starting point for each identity action.
Joiner. HR completes the hire in Sage People. Joinly reads the new Team Member and Employment Record, determines the role from attributes like HR Department, Team and job title, then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the start date on the employment record.
Mover. When someone changes Team, HR Department or manager in Sage People, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual job.
Leaver. On the leaving date recorded in Sage People, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and the account is retired on a schedule you control.
Example: A mid-market services firm hires a consultant in Sage People with a start date next Monday, in its UK HR Department. Joinly reads the Team Member record, waits until the start date, creates the Entra ID account, assigns an Office E3 licence and adds the consultant to the UK-Consulting group. When that consultant later moves to a delivery team under a new manager, Joinly swaps the groups the same day and keeps the UPN stable.
What manual user management costs
Without automation, every account starts as a Sage People ticket or a line in a spreadsheet that IT works through by hand. Microsoft’s native Salesforce provisioning can move a user across, but it targets the Salesforce User object rather than the Sage People HR record and maps nothing from HR structure to groups — so the part that actually decides access still falls to people.
Onboarding delays. New joiners wait for accounts, licences and group access while a ticket sits in a queue, losing productive days in their first week.
Permissions that don’t keep up (privilege creep). When movers change Team or HR Department, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money.
Joinly vs. the native Salesforce provisioning app
Because Sage People runs on Salesforce, the native comparison is Microsoft’s Entra provisioning for Salesforce. It’s a fine baseline for the Salesforce login, but it stops short of the part that actually decides access for a Sage People-driven setup.
Joinly | Entra Salesforce provisioning app | |
|---|---|---|
Source | Reads Sage People Team Member / Employment Record via the Salesforce API | Reads the Salesforce User object in the org |
Role-to-group mapping | Built in, rule-based on HR Department, Team and Business Unit | Manual expression mappings; no role-to-group out of the box |
HR record vs Salesforce login | Drives access from the HR person record | Tied to the licensed Salesforce User |
Manager resolution | Resolves the manager lookup between team members | Limited attribute mapping |
Licence assignment | Driven by role / attributes | Manual or group-based only |
On-premise AD | Yes, own agent plus the native Microsoft agent | Not designed for HR-driven on-prem AD |
Audit trail | Per-action logging tied to the HR source | Limited |
Watch-outs when connecting Sage People to Microsoft Entra ID
A few Sage People-specific details decide whether this connection stays reliable at scale.
It’s a Salesforce org, not a plain HR feed. Sage People data lives in Salesforce, so access is via a Connected App with OAuth and is subject to Salesforce sharing rules, permission sets and API limits. Joinly authenticates as a scoped, API-only integration user with just the read access it needs, so provisioning is reliable without over-permissioning the connection.
Team Member vs Salesforce User. The Sage People Team Member (the HR person record) is not the same as the Salesforce User (a licensed login). A naive sync that follows the Salesforce User misses HR movers and leavers. Joinly drives everything from the Team Member and Employment Record, so the HR record decides access.
Mapping HR structure to Entra groups. HR Department, Team and Business Unit don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from those structures to the correct groups and licences, so role drives access rather than manual assignment.
Resolving the manager link. The manager is a lookup between Team Member records, not a plain text field. Joinly resolves that link so the correct manager lands on the Entra ID account and org-based rules evaluate correctly.
UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, department code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Sage People change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a mid-market pharmaceutical company with around 3,200 employees across research, manufacturing and commercial teams, running Sage People on Salesforce as its HR core while identity provisioning never quite keeps up. The native Salesforce provisioning handles the licensed Salesforce logins, yet the people who never touch Salesforce — lab technicians, plant operators, field reps — still get their Entra ID accounts created by hand, and internal transfers between HR Departments leave old group access behind.
Connect Sage People to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each Team Member change at the source through the Salesforce API and acts on it automatically: new hires have their account, Office licence and group access ready on their start date, transfers between teams swap the right groups the same day, and leavers are disabled on their leaving date with a 30-day soft-delete grace window.
“Half our workforce never logs into Salesforce, so the native provisioning simply didn’t see them. Now every account is ready on the start date from the HR record, and we can show the auditor exactly which Sage People change created every bit of access.” — Head of IT, pharmaceutical company
The outcome this setup is designed for: onboarding drops from days to zero touch, privilege creep from old teams stops, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone Sage People to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Sage People to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the Sage People integration in the Joinly marketplace
Open the Joinly marketplace and search for the Sage People integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Sage People integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Sage People connection details: your Salesforce org URL (My Domain / instance) and the OAuth Connected App credentials for an API-only integration user with the Sage People Native API permission set. We only ask for the information needed to establish a successful connection with Sage People. All data is encrypted and stored securely.

Enter your Salesforce org URL and Connected App OAuth credentials in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Sage People Team Member fields.
Frequently asked questions
How do I map the manager? Reference the manager lookup on the Team Member and Joinly resolves the link to the right manager automatically.
How do I drive access from the HR record? Map from the Team Member and Employment Record rather than the Salesforce User, so people who don’t hold a Salesforce seat are still provisioned.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map Sage People fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Sage People should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Sage People flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the leaving date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Sage People to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Sage People to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Sage People reach Entra ID quickly without waiting for a nightly batch.
How does Joinly connect to Sage People?
Sage People is built on Salesforce, so Joinly connects through a Salesforce Connected App using OAuth 2.0 and reads the HR objects — Team Member and Employment Record — as a scoped, API-only integration user. It does not depend on a person holding a Salesforce login.
Does Joinly provision people who don’t use Salesforce?
Yes. Joinly drives provisioning from the Sage People Team Member record, not the Salesforce User, so employees who never log into Salesforce still get their Entra ID accounts created, updated and disabled from their HR record.
Which attributes sync from Sage People to Entra ID?
Name, email / UPN, department, job title, manager, HR Department, Business Unit, and start and end date. Additional Team Member fields can be mapped via Liquid templates.
Do I still need the native Salesforce provisioning app?
No. Joinly takes over the provisioning and role-to-group mapping from the HR record that the native Salesforce app does manually or not at all, and maintains it as your Sage People data changes.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Sage People to Active Directory guide.


