Automate onboarding & offboarding from AFAS to Entra
AFAS integration with Entra ID
Let IT automatically adapt to HR processes. New employees receive immediate access to the right systems, job changes are processed automatically, and upon termination, access is immediately revoked. This facilitates faster, more consistent onboarding and offboarding without manual steps.
- AFAS as your central place for HR data
- ISO27001 certified


Why would you integrate AFAS with Entra ID via Joinly
Automate identity management with AFAS
In many organisations, errors, delays, and security risks arise because HR systems and IT environments operate separately. With Joinly's HR ↔ Microsoft Entra ID integration, you can use your HR system as the central source for identity management. This way, accounts, roles, and access are automatically synchronised based on HR data, without manual actions.
Automatic onboarding, offboarding and changes
New employees are automatically created in Entra as soon as they appear in AFAS. No tickets, no waiting times, and instantly productive from day one.
Better security & compliance
Access is automatically adjusted with role changes and immediately revoked upon termination of employment. This helps prevent zombie accounts and makes it easier to comply with security and audit requirements.
Less management, more control
IT no longer needs to manage manual accounts. Everything is handled centrally, predictably, and transparently via Joinly with logging, monitoring, and error handling.
Save on software costs
Nothing is more annoying than paying for something you don't use. Joinly automatically deactivates accounts that are not used.
"We were able to move extremely quickly, and the flexibility of setting up the integration is a huge plus for us"
How does the integration work?
Four moments in an employment, the same pattern every time: AFAS leads and Joinly carries out the consequences.
- Onboard employee
Employee is created in AFAS
As soon as a new employee is created in AFAS , a new account is automatically created in Entra ID.
Employee changes role and/or department
A position change in AFAS may affect the applications and/or rights that the employee has access to. The job change is automatically retrieved by Joinly and synchronized to Entra ID.
- AFAS: From: HR Manager - To: Senior HR Manager
Employee data is being modified
Joinly retrieves the updated data from the HR-system and ensures that the changes are automatically applied to Entra ID.
With Joinly workflows, you can link emails, notifications or ITSM-tooling to the employee cycles.
- AFAS: From: HR Manager - To: Senior HR Manager
- AFAS: From: Maaike Jansen - To: Maaike Jansen - de Weerd
- Offboard employee
Employee leaves service
When an employee leaves the company, they are automatically deactivated in Entra ID by Joinly to remove rights from applications and deactivate accounts.
Frequently asked questions
Questions about this integration
The questions IT managers considering this integration ask us most. If yours is not here, put it to us during the demo.
What does the integration between AFAS and Microsoft Entra ID do?
Joinly uses AFAS as the source and Microsoft Entra ID as the destination. When someone joins in AFAS, Joinly creates the account in Microsoft Entra ID and puts the right groups and permissions on it. When the job changes, the permissions move with it. When someone leaves, the account is deactivated. Nothing for you to do, and nothing for you to remember.
What does this add to the provisioning Microsoft already offers?
Entra provisioning is good at executing, but it does not decide who should get what. Joinly puts that governance on top: roles and a permission matrix, approvals, temporary access with an end date, several HR sources side by side, and an audit trail per change. Entra executes; Joinly decides.
What does Joinly write into Microsoft Entra ID?
The user account with name, UPN, email address, employee number, manager and whichever attributes you put in the mapping, plus group memberships and licences. Joinly can also enable and disable an account, reset a password or MFA, issue a Temporary Access Pass, revoke sessions and, on departure, set an out-of-office or clear the calendar.
How does Joinly decide which permissions someone gets?
From roles, not from a per-person list. You record once which roles belong to which job, department or location, and which access items sit inside those roles — groups, licences, applications, folders. A role change in AFAS makes Joinly recalculate: what belongs is added, what no longer belongs is removed.
Can we keep an on-premises Active Directory alongside this?
Yes. The same source in AFAS can feed both Entra ID and an on-premises Active Directory, so cloud and on-premise follow the same truth. Joinly reaches the on-premises side through the Joinly Agent, which connects outbound — no inbound port, no VPN.
How quickly does a change in AFAS show up in Microsoft Entra ID?
That is yours to set with the import schedule: hourly, daily or weekly, at a time you choose. As soon as the import lands, Joinly works out the consequences and provisioning to Microsoft Entra ID can run straight after it. An overnight import means, in practice, that the account is ready the next morning.
What exactly happens when someone leaves?
On the date from AFAS, Joinly revokes the access: the account in Microsoft Entra ID is switched off, group memberships and permissions lapse, and connected applications are taken along. Whatever else has to happen — releasing a licence, converting the mailbox to shared, informing the manager — is arranged as a workflow, so it is part of the same process instead of a loose task.
Will Joinly touch our existing accounts in Microsoft Entra ID?
Not unasked. Joinly first imports what is in Microsoft Entra ID and matches those accounts to the employees from AFAS. Existing accounts are recognised and adopted rather than created twice; which matching strategy applies — person identifier, employee number or UPN — is yours to choose. Accounts that are not employees, such as service accounts, can be filtered out of the integration.
Can we try it without risk first?
Yes. You run the import as a dry run and get an Excel export of exactly what would happen, without anything being written. A threshold then keeps protecting you: if the source delivers more new, activated or deactivated employees in one run than you allowed, Joinly blocks the run.
What do we need to get started?
Access to your AFAS environment for the employee data, and an app registration in your Microsoft tenant that lets Joinly work over Microsoft Graph. Nothing else: nothing is installed on your own servers. Joinly tracks the client secret's expiry itself and warns you well in advance.
Is the integration secure, and can we prove it afterwards?
Joinly is ISO27001-certified. Every change is recorded, so per employee you can look back at which access was granted when, on the basis of which role, and when it was revoked again. That is precisely what an auditor or a NIS2 assessment asks of you.
What does this integration cost?
The integration is part of the subscription — you pay per account per month, not per connector or per target system. The pricing page shows what the plans cost and what each one includes.
More about AFAS
Integrating AFAS with Joinly: Automatic user management
AFAS Profit is the central source for HRM, payroll, and personnel management for many organizations. But as long as AFAS is not connected to the rest of your applications, user management remains a manual and error-prone process.
The challenge: manual user management
AFAS contains up-to-date, reliable personnel data, but without a direct integration with your IT landscape, problems arise:
IT manages accounts manually via Excel, email, or separate lists
Employees unnecessarily wait for access to systems upon hiring
Accounts of departed employees remain active for too long
HR and IT work separately, resulting in inconsistencies
All of this leads to increased risks of data breaches, loss of productivity, and unnecessary workload for IT management.
The solution: integrating AFAS via Joinly
Joinly offers a robust, proven integration between AFAS and all your business software. We automate the entire process of user provisioning and deprovisioning, based on the data in your AFAS HR administration.
What this integration delivers:
New employees automatically receive accounts in the applications they need
Changes in position, department, or contract are immediately reflected in all your applications
Accounts are automatically deactivated upon termination
HR takes the lead; IT no longer has to perform manual actions
With the AFAS integration, a streamlined chain from HR to IT is created. This improves security, increases efficiency, and shortens the time-to-productivity during onboarding.
Certified AFAS integration partner
Joinly (KoppelHet) is certified by AFAS as an integration partner. This ensures that you have an integration that has been checked and certified by AFAS itself. For example, check our integration with Entra ID / Active Directory on AFAS's page: https://partner.afas.nl/product-prs/artikel?BiId=17349
Where to go next

Everything about the AFAS integration
Which data Joinly takes out of AFAS, how often that happens and which other systems it goes on to.
See the AFAS integration
Connect AFAS to (Azure) Active Directory
The same source in AFAS, with (Azure) Active Directory as the destination. If you run hybrid, one source feeds both.
See the (Azure) Active Directory integration
Further reading
Profit 8 Entra ID koppeling: wat de AFAS-koppeling doet en waar Joinly verder gaat
De Profit 8 Entra ID koppeling synchroniseert AFAS-gebruikersgroepen naar Entra ID. Ontdek wat de koppeling doet, waar ze stopt en hoe Joinly verder gaat.
How do I set up role-based access control (RBAC) and least privilege for a municipality?
Start with the roles in your HR system and map them to roles, not to individual permissions per person. Group each role with precisely the access required for the job, adhering to the principle of least privilege. Manage these roles centrally and let an orchestration layer automatically assign and revoke them. This keeps access predictable, limited and demonstrable.
Wat betekent de Cyberbeveiligingswet (NIS2) voor het toegangsbeheer van gemeenten, provincies en waterschappen?
Gemeenten, provincies en waterschappen worden onder de Cyberbeveiligingswet automatisch aangewezen als essentiële entiteit, ongeacht hun omvang, en vallen daarmee onder proactief toezicht. Toegangsbeheer is een vast onderdeel van de zorgplicht: toegang moet beperkt, rolgebaseerd en aantoonbaar zijn. Geautomatiseerd accountbeheer met logging is de praktische manier om daaraan te voldoen.
How do I automatically revoke all access for an employee upon offboarding?
Link the HR system to an orchestration layer above Microsoft Entra ID or Google Workspace. As soon as the end-of-employment date is registered in the HR system, this layer automatically revokes or suspends the account and all linked permissions at that exact moment. This prevents active accounts of departed employees and records every change in a log.
Wat vraagt de Baseline Informatiebeveiliging Overheid op het gebied van toegangsbeheer voor medewerkers?
De Baseline Informatiebeveiliging Overheid vraagt dat toegang voor medewerkers gecontroleerd wordt verleend, beperkt blijft tot wat nodig is voor de functie, periodiek wordt beoordeeld en bij vertrek direct wordt ingetrokken. Kort gezegd: rolgebaseerde toegang, least privilege, logging en een sluitende levenscyclus van accounts. Door het personeelssysteem te koppelen aan de werkomgeving automatiseer je precies die eisen.
Browsing is free
Schedule a free demo
In 30 minutes, we would love to show you how Joinly adds value to your entire organisation.
Schedule a demo