Skip to main content
Joinly by KoppelHet

Automate onboarding & offboarding from AFAS to Active Directory

AFAS integrate with (Azure) Active Directory

Let IT automatically adapt to HR processes. New employees receive immediate access to the right systems, job changes are processed automatically, and upon termination, access is immediately revoked. This facilitates faster, more consistent onboarding and offboarding without manual steps.

  • Cloud-only (Entra ID) and Hybrid AD (Entra ID + on-premises)
  • ISO27001 & NIS2 compliant
  • Microsoft integration partner
AFAS koppelingActive Directory

Why would you integrate AFAS link with Active Directory via Joinly

Automate identity management with afas

In many organisations, errors, delays, and security risks arise because HR systems and IT environments operate separately. With Joinly's HR ↔ Microsoft Entra ID integration, you can use your HR system as the central source for identity management. This way, accounts, roles, and access are automatically synchronised based on HR data, without manual actions.

  • Automatic onboarding, offboarding and changes

    New employees are automatically created in your Active Directory as soon as they are in AFAS . No tickets, no waiting times, and immediately productive from day one.

  • Better security & compliance

    Access is automatically adjusted with role changes and immediately revoked upon termination of employment. This helps prevent zombie accounts and makes it easier to comply with security and audit requirements.

  • Less management, more control

    IT no longer needs to manage manual accounts. Everything is handled centrally, predictably, and transparently via Joinly with logging, monitoring, and error handling.

  • Save on software costs

    Nothing is more annoying than paying for something you don't use. Joinly automatically deactivates accounts that are not used.

"We were able to move extremely quickly, and the flexibility of setting up the integration is a huge plus for us"
Wilvert Blauwendraad - IT Manager Dael

How does the integration work?

Four moments in an employment, the same pattern every time: AFAS leads and Joinly carries out the consequences.

  1. Onboard employee

    Employee is created in AFAS

    As soon as a new employee is created in AFAS , a new account is automatically created in Entra ID.

  2. Employee changes job title and/or department

    A position change in AFAS may affect the applications and/or rights that the employee has access to. The job change is automatically retrieved by Joinly and synchronized to Entra ID.

    • : From: HR Manager - To: Senior HR Manager
  3. Employee data is being modified

    Joinly retrieves the updated data from the HR-system and ensures that the changes are automatically applied to Entra ID.

    With Joinly workflows, you can link emails, notifications or ITSM-tooling to the employee cycles.

    • : From: HR Manager - To: Senior HR Manager
    • : From: Maaike Jansen - To: Maaike Jansen - de Weerd
  4. Offboard employee

    Employee leaves service

    When an employee leaves the company, they are automatically deactivated in Entra ID by Joinly to remove rights from applications and deactivate accounts.

Frequently asked questions

Questions about this integration

The questions IT managers considering this integration ask us most. If yours is not here, put it to us during the demo.

  • What does the integration between AFAS and (Azure) Active Directory do?

    Joinly uses AFAS as the source and (Azure) Active Directory as the destination. When someone joins in AFAS, Joinly creates the account in (Azure) Active Directory and puts the right groups and permissions on it. When the job changes, the permissions move with it. When someone leaves, the account is deactivated. Nothing for you to do, and nothing for you to remember.

  • Does this work if we are not cloud-only yet?

    That is exactly what it is for. Joinly reaches your on-premises Active Directory through the Joinly Agent: a lightweight service in your own network that connects outbound. No inbound port has to be opened and no VPN is needed. Hybrid organisations get the same automation as cloud-only customers.

  • What does Joinly write into (Azure) Active Directory?

    The AD account in the right OU, with name, UPN, email address, employee number, manager and whichever attributes you put in the mapping, plus membership of your on-premises groups. On a hybrid Exchange, Joinly can create the remote mailbox as well.

  • How does Joinly decide which permissions someone gets?

    From roles, not from a per-person list. You record once which roles belong to which job, department or location, and which access items sit inside those roles — groups, licences, applications, folders. A role change in AFAS makes Joinly recalculate: what belongs is added, what no longer belongs is removed.

  • Can we drive Microsoft Entra ID alongside this?

    Yes. The same source in AFAS can feed both your on-premises Active Directory and Microsoft Entra ID. Joinly reaches Entra ID directly over Microsoft Graph, with its own app registration in your tenant.

  • How quickly does a change in AFAS show up in (Azure) Active Directory?

    That is yours to set with the import schedule: hourly, daily or weekly, at a time you choose. As soon as the import lands, Joinly works out the consequences and provisioning to (Azure) Active Directory can run straight after it. An overnight import means, in practice, that the account is ready the next morning.

  • What exactly happens when someone leaves?

    On the date from AFAS, Joinly revokes the access: the account in (Azure) Active Directory is switched off, group memberships and permissions lapse, and connected applications are taken along. Whatever else has to happen — releasing a licence, converting the mailbox to shared, informing the manager — is arranged as a workflow, so it is part of the same process instead of a loose task.

  • Will Joinly touch our existing accounts in (Azure) Active Directory?

    Not unasked. Joinly first imports what is in (Azure) Active Directory and matches those accounts to the employees from AFAS. Existing accounts are recognised and adopted rather than created twice; which matching strategy applies — person identifier, employee number or UPN — is yours to choose. Accounts that are not employees, such as service accounts, can be filtered out of the integration.

  • Can we try it without risk first?

    Yes. You run the import as a dry run and get an Excel export of exactly what would happen, without anything being written. A threshold then keeps protecting you: if the source delivers more new, activated or deactivated employees in one run than you allowed, Joinly blocks the run.

  • What do we need to get started?

    Access to your AFAS environment for the employee data, and the Joinly Agent on a server in your own network. It only connects outbound, so there is no inbound firewall rule to open and no VPN to set up.

  • Is the integration secure, and can we prove it afterwards?

    Joinly is ISO27001-certified. Every change is recorded, so per employee you can look back at which access was granted when, on the basis of which role, and when it was revoked again. That is precisely what an auditor or a NIS2 assessment asks of you.

  • What does this integration cost?

    The integration is part of the subscription — you pay per account per month, not per connector or per target system. The pricing page shows what the plans cost and what each one includes.

More about AFAS

Integrating AFAS with Joinly: Automatic user management

AFAS Profit is the central source for HRM, payroll, and personnel management for many organizations. But as long as AFAS is not connected to the rest of your applications, user management remains a manual and error-prone process.



The challenge: manual user management

AFAS contains up-to-date, reliable personnel data, but without a direct integration with your IT landscape, problems arise:

  • IT manages accounts manually via Excel, email, or separate lists

  • Employees unnecessarily wait for access to systems upon hiring

  • Accounts of departed employees remain active for too long

  • HR and IT work separately, resulting in inconsistencies

All of this leads to increased risks of data breaches, loss of productivity, and unnecessary workload for IT management.



The solution: integrating AFAS via Joinly

Joinly offers a robust, proven integration between AFAS and all your business software. We automate the entire process of user provisioning and deprovisioning, based on the data in your AFAS HR administration.

What this integration delivers:

  • New employees automatically receive accounts in the applications they need

  • Changes in position, department, or contract are immediately reflected in all your applications

  • Accounts are automatically deactivated upon termination

  • HR takes the lead; IT no longer has to perform manual actions

With the AFAS integration, a streamlined chain from HR to IT is created. This improves security, increases efficiency, and shortens the time-to-productivity during onboarding.



Certified AFAS integration partner

Joinly (KoppelHet) is certified by AFAS as an integration partner. This ensures that you have an integration that has been checked and certified by AFAS itself. For example, check our integration with Entra ID / Active Directory on AFAS's page: https://partner.afas.nl/product-prs/artikel?BiId=17349

Where to go next

Further reading

See all integrations

Browsing is free

Schedule a demo

In 30 minutes, we would love to show you how Joinly adds value to the entire organisation.

Schedule a demo