Connect Securex to Microsoft Entra ID

Connect Securex to Microsoft Entra ID

Connect Securex to Microsoft Entra ID

When someone joins, moves or leaves in Securex, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Securex to Microsoft Entra ID, Joinly reads each HR change from the Securex HR platform (Exact Officient) at the source — through the Officient REST API — and applies it automatically to the right account. Securex stays your source of truth for people, teams and contracts; Joinly is the engine that keeps every account accurate and traceable.

Key takeaways

  • Your Securex HR platform (Exact Officient) stays the source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically.

  • Joinly reads people, teams, functions and contracts from the Officient REST API and maps them to the right Entra ID groups and licences — something no native Securex connector does.

  • Joinly separates the two Securex data planes: it reads the live HR employee data from Officient, not the periodic payroll files that go to your sociaal-secretariaat advisor.

  • Bilingual NL/FR names, functions and team labels are handled with diacritic-safe display-name and UPN rules, so a Dutch or French record produces a clean, unique account.

  • Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.

Securex

Joiner

Mover

Leaver

Microsoft Entra ID (formerly Azure AD)

Quick facts

Source system

Securex HR platform (Exact Officient)

Target system

Microsoft Entra ID (formerly Azure AD)

Connection method

Officient REST API (api.officient.io) → Entra ID

Supported events

Joiner, mover, leaver (incl. rehire and contract changes)

Synced attributes

Name, email / UPN, function (job title), team, department, manager, employee number, start and end date

Authentication

Bearer access token (OAuth2 authorize/token flow with long-lived refresh token)

Real-time or batch

Frequent sync, multiple times per day

Compliance

ISO 27001, NIS2-ready, GDPR (EU data centre)

How does Joinly sync Securex to Microsoft Entra ID?

Joinly reads each HR change from your Securex HR platform (Exact Officient) through the Officient REST API and applies it to the matching Entra ID account automatically. Officient holds the authoritative people, team and contract records, so it is the starting point for each identity action — while the payroll data that flows to your Securex sociaal-secretariaat advisor stays where it belongs.

  1. Joiner. HR completes the hire in the Securex/Officient platform. Joinly reads the new person, their team, function and contract, and determines the role from those attributes. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the contract start date.

  2. Mover. When someone changes function, team or department in Officient, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new role is revoked, so permissions stay aligned with the actual job.

  3. Leaver. On the contract end date recorded in Officient, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and a soft-delete grace window keeps the account recoverable for a set period before it is retired.

Example: A Belgian services company runs its HR in the Securex/Officient platform and hires a project coordinator in the Antwerp team with a start date next Monday. Joinly reads the new person and contract, waits until the start date, creates the Entra ID account, assigns a Microsoft 365 licence and adds the coordinator to the BE-Projects group. Because the record is in French, Joinly applies its diacritic-safe UPN rule so the login is clean and unique from day one.

What manual user management costs

Without automation, every account starts as an email from HR or a line in a spreadsheet that IT works through by hand. Securex’s HR platform holds the people and contract data, but there is no first-party connector that turns a new hire in Officient into a provisioned Entra ID account — so the part that actually decides access still falls to people.

  • Onboarding delays. New joiners wait for accounts, licences and group access while a request sits in a queue, losing productive days in their first week.

  • Permissions that don’t keep up (privilege creep). When movers change function or team, old access often stays attached, so people accumulate rights they no longer need.

  • Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused Microsoft 365 licences keep costing money after someone’s contract has ended.

Joinly vs. a custom Officient API integration

Securex has no native Entra ID provisioning connector, so the realistic alternative is scripting against the Officient REST API yourself or wiring it through a generic iPaaS. Here’s how that compares with Joinly for a Securex/Officient-driven setup.


Joinly

Custom Officient API / iPaaS

Source

Reads the Officient REST API directly

You build and maintain the API calls yourself

Role-to-group mapping

Built in, rule-based on teams and functions

Hand-coded; you own every rule

Bilingual NL/FR data

Diacritic-safe display-name and UPN rules

Custom string handling; easy to get wrong

Licence assignment

Driven by role / attributes

Manual or scripted

On-premise AD

Yes, own agent plus the native Microsoft agent

Separate build; not covered by the API alone

Audit trail

Per-action logging tied to the HR source

Whatever you log yourself

Watch-outs when connecting Securex to Microsoft Entra ID

A few Securex-specific details decide whether this connection stays reliable at scale.

  • Read HR, not the payroll batch. Securex runs two data planes: the live HR platform (Officient) and the payroll files that periodically go to your sociaal-secretariaat klantenadviseur. Provisioning should be driven by the live HR data, so Joinly reads the Officient REST API rather than any monthly payroll export.

  • Bilingual NL/FR records. Depending on the region and entity, names, functions and team labels arrive in Dutch or French, often with accented characters. A naive UPN or display-name rule produces inconsistent or invalid logins. Joinly applies diacritic-safe transformation so every account is clean and predictable.

  • Mapping teams and functions to Entra groups. Officient models a person through their team and function rather than a deep legal-entity hierarchy. Joinly builds explicit rules from teams and functions to the correct Entra ID groups and licences, so role drives access rather than manual assignment.

  • Employee number availability. The linked payroll employee number is only exposed on certain Securex/Officient integrations. Joinly doesn’t assume it is present — it derives a stable identifier from the fields your tenant actually returns, so matching never breaks when the number is absent.

  • UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, team code or controlled tiebreaker — so every UPN is unique and predictable from day one.

Joinly handles each of these by default with custom mapping and transformation.

Always audit-ready

Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Securex change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.

Example case

Picture a Belgian care organisation with around 1,800 employees across a dozen residential and home-care sites, running its HR in the Securex/Officient platform while its identity provisioning never quite keeps up. HR enters each new carer, nurse or support worker in Officient, but IT still creates the Entra ID account by hand from an email — and with fixed-term contracts, bank staff and frequent team changes, the queue never empties. New joiners wait until day two or three for their Microsoft 365 access, and leavers on an expired contract sometimes keep an active account for weeks.

Connect Securex to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change in the Officient platform at the source and acts on it automatically: new carers have their account, licence and group access ready on their contract start date, a move to another team swaps the right groups the same day, French and Dutch records both produce a clean UPN, and leavers are disabled on their contract end date with a 30-day soft-delete grace window.

“Our carers used to lose their first days chasing a login. Now the account is simply ready on the start date, a team change updates access by itself, and we can show the auditor exactly which Securex change created every bit of access.” — Head of IT, care organisation

The outcome this setup is designed for: onboarding drops from days to zero touch, expired-contract accounts stop lingering, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.

More than a connector

A standalone Securex to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.

Schedule a demo

Installation manual

Installation manual

Connect Securex to Microsoft Entra ID

Connect Securex to Microsoft Entra ID

Installation guide

Follow these steps to connect Securex to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.

1. Create your account

Go to platform.joinly.app and create your account.

Note: charges may apply for using the platform after the trial period ends.


Joinly account creation screen at platform.joinly.app


Sign up at platform.joinly.app to get started.

2. Connect your Microsoft account

Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.


Joinly identity provider setup screen for connecting a Microsoft Entra tenant


Connect your Microsoft tenant and pick your scopes.

3. Import your existing accounts from Entra ID

Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.

4. Find the Securex integration in the Joinly marketplace

Open the Joinly marketplace and search for the Securex (Officient) integration.

Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.


Joinly marketplace showing available HR integrations


Search the marketplace for the Securex integration.

5. Follow the installation wizard

You may be redirected to integrations.joinly.app. Create an account there and enter your Securex/Officient connection details: authorise Joinly through the OAuth2 flow, or paste an access token generated in the Exact Officient developer menu. Joinly stores the refresh token so the connection keeps itself alive. We only ask for the information needed to establish a successful connection with the Officient API. All data is encrypted and stored securely.


Joinly installation wizard for entering Securex Officient connection details


Authorise Joinly against the Officient API or paste your access token in the wizard.

6. Configure your field mapping

Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Officient fields such as name parts, team, function and contract dates.

Frequently asked questions

  • How do I map the manager? Reference the manager on the person record in the mapping and Joinly resolves the link to the right manager automatically.

  • How do I handle French and Dutch records? Use a diacritic-safe transform in the template so accented names still produce a valid, consistent UPN.

  • How do I prevent duplicate usernames? Use the generateUniqueUsername helper, which falls back to the next pattern when the first one is already taken:
    {{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}


Joinly field mapping screen for Securex Officient attributes using Liquid templates


Map Officient fields to Entra ID attributes with Liquid templates.

7. Configure the scheduled import

At platform.joinly.app/settings/import-configs, configure how often the import from Securex/Officient should run.

8. Configure your workflows

Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in the Officient platform flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the contract end date (for example 30 days) to retire accounts safely.


Joinly workflow editor creating an employee onboarding workflow


Create a trigger-based onboarding workflow.


Adding the create or update employee in Entra action to a workflow


Add the create/update action, then set your matching strategy and field mapping.


Adding the Entra soft delete action to remove accounts on employee leave


Add the Entra soft delete action to retire accounts safely.

## AD on-premise support

Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Securex to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.

Frequently asked questions

Does the Securex to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in your Securex/Officient HR platform reach Entra ID quickly without waiting for a nightly batch.

Which Securex system does Joinly actually read?
The live HR employee data in the Securex HR platform (Exact Officient), through the Officient REST API. Joinly does not depend on the periodic payroll files that go to your sociaal-secretariaat advisor, so provisioning is driven by up-to-date HR data.

How does Joinly authenticate to Securex/Officient?
Through the Officient API with a Bearer access token. You either authorise Joinly via the OAuth2 flow or paste a token generated in the Exact Officient developer menu; Joinly then uses the long-lived refresh token to keep the connection alive.

Which attributes sync from Securex to Entra ID?
Name, email / UPN, function (job title), team, department, manager, employee number and contract start and end dates. Fields are mapped to Entra ID attributes with Liquid templates, including diacritic-safe rules for French and Dutch records.

Is there a native Securex connector for Entra ID instead?
No first-party Securex connector provisions Entra ID. The alternative is scripting against the Officient API yourself or using a generic iPaaS. Joinly provides the provisioning, role-to-group mapping and leaver handling out of the box and maintains it as your Securex data changes.

Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Securex to Active Directory guide.

Request installation support