Automate onboarding & offboarding from BCS to Entra
BCS integration with Entra ID
Let IT automatically adapt to HR processes. New employees receive immediate access to the right systems, job changes are processed automatically, and upon termination, access is immediately revoked. This facilitates faster, more consistent onboarding and offboarding without manual steps.
- BCS as your central place for HR data
- ISO27001 certified


Why would you integrate BCS with Entra ID via Joinly
Automate identity management with BCS
In many organisations, errors, delays, and security risks arise because HR systems and IT environments operate separately. With Joinly's HR ↔ Microsoft Entra ID integration, you can use your HR system as the central source for identity management. This way, accounts, roles, and access are automatically synchronised based on HR data, without manual actions.
Automatic onboarding, offboarding and changes
New employees are automatically created in Entra as soon as they appear in BCS . No tickets, no waiting times, and immediately productive from day one.
Better security & compliance
Access is automatically adjusted with role changes and immediately revoked upon termination of employment. This helps prevent zombie accounts and makes it easier to comply with security and audit requirements.
Less management, more control
IT no longer needs to manage manual accounts. Everything is handled centrally, predictably, and transparently via Joinly with logging, monitoring, and error handling.
Save on software costs
Nothing is more annoying than paying for something you don't use. Joinly automatically deactivates accounts that are not used.
"We were able to move extremely quickly, and the flexibility of setting up the integration is a huge plus for us"
How does the integration work?
Four moments in an employment, the same pattern every time: BCS leads and Joinly carries out the consequences.
- Onboard employee
Employee is created in BCS
As soon as a new employee is created in BCS , a new account is automatically created in Entra ID.
Employee changes role and/or department
A position change in BCS may affect the applications and/or rights that the employee has access to. The job change is automatically retrieved by Joinly and synchronized to Entra ID.
- BCS: From: HR Manager - To: Senior HR Manager
Employee data is being modified
Joinly retrieves the updated data from the HR-system and ensures that the changes are automatically applied to Entra ID.
With Joinly workflows, you can link emails, notifications or ITSM-tooling to the employee cycles.
- BCS: From: HR Manager - To: Senior HR Manager
- BCS: From: Maaike Jansen - To: Maaike Jansen - de Weerd
- Offboard employee
Employee leaves service
When an employee leaves the company, they are automatically deactivated in Entra ID by Joinly to remove rights from applications and deactivate accounts.
Frequently asked questions
Questions about this integration
The questions IT managers considering this integration ask us most. If yours is not here, put it to us during the demo.
What does the integration between BCS and Microsoft Entra ID do?
Joinly uses BCS as the source and Microsoft Entra ID as the destination. When someone joins in BCS, Joinly creates the account in Microsoft Entra ID and puts the right groups and permissions on it. When the job changes, the permissions move with it. When someone leaves, the account is deactivated. Nothing for you to do, and nothing for you to remember.
What does this add to the provisioning Microsoft already offers?
Entra provisioning is good at executing, but it does not decide who should get what. Joinly puts that governance on top: roles and a permission matrix, approvals, temporary access with an end date, several HR sources side by side, and an audit trail per change. Entra executes; Joinly decides.
What does Joinly write into Microsoft Entra ID?
The user account with name, UPN, email address, employee number, manager and whichever attributes you put in the mapping, plus group memberships and licences. Joinly can also enable and disable an account, reset a password or MFA, issue a Temporary Access Pass, revoke sessions and, on departure, set an out-of-office or clear the calendar.
How does Joinly decide which permissions someone gets?
From roles, not from a per-person list. You record once which roles belong to which job, department or location, and which access items sit inside those roles — groups, licences, applications, folders. A role change in BCS makes Joinly recalculate: what belongs is added, what no longer belongs is removed.
Can we keep an on-premises Active Directory alongside this?
Yes. The same source in BCS can feed both Entra ID and an on-premises Active Directory, so cloud and on-premise follow the same truth. Joinly reaches the on-premises side through the Joinly Agent, which connects outbound — no inbound port, no VPN.
How quickly does a change in BCS show up in Microsoft Entra ID?
That is yours to set with the import schedule: hourly, daily or weekly, at a time you choose. As soon as the import lands, Joinly works out the consequences and provisioning to Microsoft Entra ID can run straight after it. An overnight import means, in practice, that the account is ready the next morning.
What exactly happens when someone leaves?
On the date from BCS, Joinly revokes the access: the account in Microsoft Entra ID is switched off, group memberships and permissions lapse, and connected applications are taken along. Whatever else has to happen — releasing a licence, converting the mailbox to shared, informing the manager — is arranged as a workflow, so it is part of the same process instead of a loose task.
Will Joinly touch our existing accounts in Microsoft Entra ID?
Not unasked. Joinly first imports what is in Microsoft Entra ID and matches those accounts to the employees from BCS. Existing accounts are recognised and adopted rather than created twice; which matching strategy applies — person identifier, employee number or UPN — is yours to choose. Accounts that are not employees, such as service accounts, can be filtered out of the integration.
Can we try it without risk first?
Yes. You run the import as a dry run and get an Excel export of exactly what would happen, without anything being written. A threshold then keeps protecting you: if the source delivers more new, activated or deactivated employees in one run than you allowed, Joinly blocks the run.
What do we need to get started?
Access to your BCS environment for the employee data, and an app registration in your Microsoft tenant that lets Joinly work over Microsoft Graph. Nothing else: nothing is installed on your own servers. Joinly tracks the client secret's expiry itself and warns you well in advance.
Is the integration secure, and can we prove it afterwards?
Joinly is ISO27001-certified. Every change is recorded, so per employee you can look back at which access was granted when, on the basis of which role, and when it was revoked again. That is precisely what an auditor or a NIS2 assessment asks of you.
What does this integration cost?
The integration is part of the subscription — you pay per account per month, not per connector or per target system. The pricing page shows what the plans cost and what each one includes.
More about BCS
BCS koppeling met Joinly: automatisering van gebruikersbeheer
Voor veel organisaties is BCS hét centrale HR-systeem voor personeels- en salarisadministratie. Het platform bevat alle cruciale medewerkersgegevens, maar zonder koppeling met je IT-omgeving leidt dit al snel tot veel handmatig werk en foutgevoelige processen.
De uitdagingen zonder koppeling
Wanneer BCS niet geïntegreerd is met je applicaties, ontstaan herkenbare problemen:
Nieuwe medewerkers wachten dagen op toegang tot systemen en applicaties
Accounts worden nog via Excel of losse verzoeken bij IT beheerd
Vertrokken medewerkers behouden soms onterecht toegang, wat beveiligingsrisico’s veroorzaakt
HR-gegevens en IT-accounts zijn niet synchroon, waardoor fouten en inconsistenties ontstaan
Het gevolg: vertraging, frustratie en een verhoogde kans op datalekken.
Het gevolg: vertraging, frustratie en een verhoogde kans op datalekken.
Hoe Joinly dit oplost
Met de BCS koppeling van Joinly wordt gebruikersbeheer volledig geautomatiseerd. Zodra HR in BCS een wijziging doorvoert zoals een indiensttreding, functiewijziging of uitdiensttreding, zorgt Joinly ervoor dat deze automatisch wordt verwerkt in alle gekoppelde applicaties.
Voordelen van de BCS koppeling
Nieuwe medewerkers krijgen direct toegang tot de juiste systemen
HR-wijzigingen worden automatisch en zonder vertraging doorgevoerd
Accounts van ex-medewerkers worden tijdig en veilig gedeactiveerd
HR is leidend, IT hoeft geen handmatig beheer meer uit te voeren
Zo verandert een complex en foutgevoelig proces in een gestroomlijnde workflow waarin HR en IT samenwerken vanuit één betrouwbare bron. Het resultaat: hogere efficiëntie, betere beveiliging en een veel snellere onboarding.
Benieuwd hoe de BCS koppeling met Joinly jouw organisatie helpt om gebruikersbeheer te vereenvoudigen en risico’s te minimaliseren? Met Joinly maak je de stap naar veilig, foutloos en toekomstbestendig Identity & Access Management.
Where to go next

Everything about the BCS integration
Which data Joinly takes out of BCS, how often that happens and which other systems it goes on to.
See the BCS integration
Connect BCS to (Azure) Active Directory
The same source in BCS, with (Azure) Active Directory as the destination. If you run hybrid, one source feeds both.
See the (Azure) Active Directory integration
Browsing is free
Schedule a free demo
In 30 minutes, we would love to show you how Joinly adds value to your entire organisation.
Schedule a demo