When someone joins, moves or leaves in Youforce, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Youforce to Microsoft Entra ID, Joinly reads each HR change from Visma | Raet at the source — through the Youforce IAM API — and applies it automatically to the right account. Youforce, backed by HR Core Beaufort or HR Core Business, stays your source of truth; Joinly is the engine that keeps every action accurate and traceable.
Key takeaways
Youforce (HR Core Beaufort or HR Core Business) stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically.
Joinly reads the Youforce IAM API — Person, Employment, Assignment, JobProfile, OrganizationUnit and RoleAssignment — and maps those structures to the right Entra ID groups and licences.
Joinly resolves manager and hierarchy from RoleAssignment and OrganizationUnit, and handles the Beaufort-vs-Business field differences (cost center and company aren’t available on Beaufort).
Authentication uses OAuth 2.0 with scoped access, registered as an App in the Visma Developer portal against your tenant — no legacy file drops into Entra ID.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | Youforce (Visma | Raet — HR Core Beaufort / HR Core Business) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Youforce IAM API → Entra ID |
Supported events | Joiner, mover, leaver (incl. rehire, transfer, role change) |
Synced attributes | Name, email / UPN, department (organization unit), job profile, manager, employment dates, and cost center where the HR core exposes it |
Authentication | OAuth 2.0 with scoped access; App registered in the Visma Developer portal (Client ID / Secret + Tenant ID) |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Youforce to Microsoft Entra ID?
Joinly reads each HR change from Youforce through the IAM API and applies it to the matching Entra ID account automatically. Youforce — running on HR Core Beaufort or HR Core Business — holds the authoritative employment record, so it is the starting point for each identity action.
Joiner. HR completes the hire in Youforce. Joinly reads the new Person, Employment and Assignment records, determines the role from the job profile, organization unit and role assignment, then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the employment start date.
Mover. When someone changes job profile, organization unit or manager in Youforce, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual job.
Leaver. On the employment end date recorded in Youforce, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and a soft-delete grace window keeps the account recoverable for a set period.
Example: A Dutch organisation runs Youforce on HR Core Beaufort and hires a policy advisor with a start date next Monday. Joinly reads the employment record, waits until the start date, creates the Entra ID account, assigns an Office E3 licence and adds the advisor to the group that matches their organization unit and job profile. When that person later transfers to another department, Joinly reads the new assignment and swaps the groups the same day, without anyone raising a ticket.
What manual user management costs
Without automation, every account starts as a Youforce export or a ticket that IT works through by hand. A generic IAM connector on the Youforce IAM API can pull the data across, but it maps roles to groups through rules you configure yourself and leaves future-dating and the Beaufort-vs-Business field differences to be handled manually — so the part that actually decides access still falls to people.
Onboarding delays. New joiners wait for accounts, licences and group access while a ticket sits in a queue, losing productive days in their first week.
Permissions that don’t keep up (privilege creep). When movers change job profile or organization unit, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money.
Joinly vs. a generic Youforce IAM connector
There is no first-party Microsoft provisioning app for Youforce, so the usual alternative is a generic IAM middleware on the Youforce IAM API or a legacy file import. Either reads the same data, but stops short of the part that actually decides access. Here’s how the two compare for a Youforce-driven setup.
Joinly | Generic IAM connector / file import | |
|---|---|---|
Source | Reads the Youforce IAM API directly | Reads the IAM API or a file export |
Role-to-group mapping | Built in, rule-based on job profile and organization unit | Manual rules; no role-to-group out of the box |
Future-dated hires | Times account creation to the employment start date | Needs custom date-window configuration |
Beaufort vs Business fields | Handles the differing field sets per HR core | Manual per-core mapping |
Licence assignment | Driven by role / attributes | Manual or group-based only |
On-premise AD | Yes, own agent plus the native Microsoft agent | Varies; often a separate file import |
Audit trail | Per-action logging tied to the HR source | Limited |
Watch-outs when connecting Youforce to Microsoft Entra ID
A few Youforce-specific details decide whether this connection stays reliable at scale.
HR Core Beaufort vs HR Core Business fields. The two HR cores expose different field sets — company and cost center, for example, are not available for HR Core Beaufort. Joinly builds the mapping against the core the customer actually runs, so nothing silently maps to an empty attribute.
Scheduled refresh, not per-event push. Youforce delivers changes on a scheduled IAM API refresh rather than an event-by-event webhook, and future-dated changes come through ahead of time. Joinly polls the modified records and times each action — including future-dated hires — to the employment start and end dates instead of the moment HR saved the record.
Manager and hierarchy from RoleAssignment. Youforce expresses manager and organisational hierarchy through RoleAssignment and OrganizationUnit rather than a single manager field. Joinly resolves those relationships so the manager attribute and group mapping reflect the real reporting line.
Mapping job profile and organization unit to Entra groups. Job profile and organization unit don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from those structures to the correct groups and licences, so role drives access rather than manual assignment.
UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, org-unit code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Youforce change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a provincial government body with around 3,500 employees across several departments and agencies, running Youforce on HR Core Beaufort as its HR core while its identity provisioning never quite keeps up. A generic connector handles the simple cases, yet secondments between departments, temporary appointments and a steady stream of role changes keep breaking it — new advisors are provisioned the moment HR saves the record rather than on their actual start date, and manager relationships that live in role assignments never make it cleanly into Entra ID.
Connect Youforce to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change from the Youforce IAM API at the source and acts on it automatically: new hires have their account, Office licence and group access ready on their employment start date, transfers between organization units swap the right groups the same day, the manager attribute is resolved from the role assignment, and leavers are disabled on their end date with a 30-day soft-delete grace window.
“Our reorganisations and secondments used to break every sync. Now an account is simply ready on the start date, a transfer just swaps the groups, and we can show the auditor exactly which Youforce change created every bit of access.” — Head of IT, provincial government body
The outcome this setup is designed for: onboarding drops from days to zero touch, privilege creep from old roles is eliminated, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone Youforce to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Youforce to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the Youforce integration in the Joinly marketplace
Open the Joinly marketplace and search for the Youforce (Visma | Raet) integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Youforce integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Youforce connection details. In the Visma Developer portal, register an App to obtain your Client ID and Client Secret, accept the invitation code so your Tenant ID becomes available, and grant the IAM scopes Joinly needs (such as Youforce-IAM:Get_Basic). We only ask for the information needed to establish a successful connection with Youforce. All data is encrypted and stored securely.

Enter your Youforce IAM API Client ID, Client Secret and Tenant ID in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Youforce fields.
Frequently asked questions
How do I map the manager? Joinly resolves the manager from the RoleAssignment and organization unit, so the manager attribute reflects the real reporting line without a manual lookup.
How do I handle the Beaufort vs Business difference? Map only the fields your HR core exposes; Joinly builds the mapping against Beaufort or Business so nothing maps to an empty attribute.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map Youforce fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Youforce should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Youforce flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the employment end date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Youforce to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Youforce to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that reads modified records from the Youforce IAM API and applies them to Entra ID, so changes reach Entra ID quickly without a manual export step.
How does Joinly connect to Youforce?
Through the Youforce IAM API using OAuth 2.0 with scoped access. You register an App in the Visma Developer portal to get the Client ID and Client Secret, accept the invitation code to obtain the Tenant ID, and grant the IAM scopes Joinly needs — no legacy file exchange required.
How does Joinly handle the difference between HR Core Beaufort and HR Core Business?
The two HR cores expose different field sets — cost center and company, for example, aren’t available on Beaufort. Joinly builds the field mapping against the core you actually run, so attributes never map to something Youforce doesn’t provide.
Which attributes sync from Youforce to Entra ID?
Name, email / UPN, department (organization unit), job profile, manager, employment start and end dates, and cost center where the HR core exposes it. Extension fields can be mapped via Liquid templates.
Do I need a separate Microsoft provisioning app for Youforce?
No. There is no first-party Microsoft inbound provisioning app for Youforce. Joinly reads the Youforce IAM API directly and takes over the role-to-group mapping, future-dating and manager resolution that a generic connector leaves to manual configuration.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Youforce to Active Directory guide.


