Automate onboarding & offboarding from HR2Day to Active Directory
HR2Day integrate with (Azure) Active Directory
Let IT automatically adapt to HR processes. New employees receive immediate access to the right systems, job changes are processed automatically, and upon termination, access is immediately revoked. This facilitates faster, more consistent onboarding and offboarding without manual steps.
- Cloud-only (Entra ID) and Hybrid AD (Entra ID + on-premises)
- ISO27001 & NIS2 compliant
- Microsoft integration partner


Why would you integrate HR2Day link with Active Directory via Joinly
Automate identity management with hr2day
In many organisations, errors, delays, and security risks arise because HR systems and IT environments operate separately. With Joinly's HR ↔ Microsoft Entra ID integration, you can use your HR system as the central source for identity management. This way, accounts, roles, and access are automatically synchronised based on HR data, without manual actions.
Automatic onboarding, offboarding and changes
New employees are automatically created in your Active Directory as soon as they are in HR2Day . No tickets, no waiting times, and immediately productive from day one.
Better security & compliance
Access is automatically adjusted with role changes and immediately revoked upon termination of employment. This helps prevent zombie accounts and makes it easier to comply with security and audit requirements.
Less management, more control
IT no longer needs to manage manual accounts. Everything is handled centrally, predictably, and transparently via Joinly with logging, monitoring, and error handling.
Save on software costs
Nothing is more annoying than paying for something you don't use. Joinly automatically deactivates accounts that are not used.
"We were able to move extremely quickly, and the flexibility of setting up the integration is a huge plus for us"
How does the integration work?
Four moments in an employment, the same pattern every time: HR2Day leads and Joinly carries out the consequences.
- Onboard employee
Employee is created in HR2Day
As soon as a new employee is created in HR2Day , a new account is automatically created in Entra ID.
Employee changes job title and/or department
A position change in HR2Day may affect the applications and/or rights that the employee has access to. The job change is automatically retrieved by Joinly and synchronized to Entra ID.
- : From: HR Manager - To: Senior HR Manager
Employee data is being modified
Joinly retrieves the updated data from the HR-system and ensures that the changes are automatically applied to Entra ID.
With Joinly workflows, you can link emails, notifications or ITSM-tooling to the employee cycles.
- : From: HR Manager - To: Senior HR Manager
- : From: Maaike Jansen - To: Maaike Jansen - de Weerd
- Offboard employee
Employee leaves service
When an employee leaves the company, they are automatically deactivated in Entra ID by Joinly to remove rights from applications and deactivate accounts.
Frequently asked questions
Questions about this integration
The questions IT managers considering this integration ask us most. If yours is not here, put it to us during the demo.
What does the integration between HR2Day and (Azure) Active Directory do?
Joinly uses HR2Day as the source and (Azure) Active Directory as the destination. When someone joins in HR2Day, Joinly creates the account in (Azure) Active Directory and puts the right groups and permissions on it. When the job changes, the permissions move with it. When someone leaves, the account is deactivated. Nothing for you to do, and nothing for you to remember.
Does this work if we are not cloud-only yet?
That is exactly what it is for. Joinly reaches your on-premises Active Directory through the Joinly Agent: a lightweight service in your own network that connects outbound. No inbound port has to be opened and no VPN is needed. Hybrid organisations get the same automation as cloud-only customers.
What does Joinly write into (Azure) Active Directory?
The AD account in the right OU, with name, UPN, email address, employee number, manager and whichever attributes you put in the mapping, plus membership of your on-premises groups. On a hybrid Exchange, Joinly can create the remote mailbox as well.
How does Joinly decide which permissions someone gets?
From roles, not from a per-person list. You record once which roles belong to which job, department or location, and which access items sit inside those roles — groups, licences, applications, folders. A role change in HR2Day makes Joinly recalculate: what belongs is added, what no longer belongs is removed.
Can we drive Microsoft Entra ID alongside this?
Yes. The same source in HR2Day can feed both your on-premises Active Directory and Microsoft Entra ID. Joinly reaches Entra ID directly over Microsoft Graph, with its own app registration in your tenant.
How quickly does a change in HR2Day show up in (Azure) Active Directory?
That is yours to set with the import schedule: hourly, daily or weekly, at a time you choose. As soon as the import lands, Joinly works out the consequences and provisioning to (Azure) Active Directory can run straight after it. An overnight import means, in practice, that the account is ready the next morning.
What exactly happens when someone leaves?
On the date from HR2Day, Joinly revokes the access: the account in (Azure) Active Directory is switched off, group memberships and permissions lapse, and connected applications are taken along. Whatever else has to happen — releasing a licence, converting the mailbox to shared, informing the manager — is arranged as a workflow, so it is part of the same process instead of a loose task.
Will Joinly touch our existing accounts in (Azure) Active Directory?
Not unasked. Joinly first imports what is in (Azure) Active Directory and matches those accounts to the employees from HR2Day. Existing accounts are recognised and adopted rather than created twice; which matching strategy applies — person identifier, employee number or UPN — is yours to choose. Accounts that are not employees, such as service accounts, can be filtered out of the integration.
Can we try it without risk first?
Yes. You run the import as a dry run and get an Excel export of exactly what would happen, without anything being written. A threshold then keeps protecting you: if the source delivers more new, activated or deactivated employees in one run than you allowed, Joinly blocks the run.
What do we need to get started?
Access to your HR2Day environment for the employee data, and the Joinly Agent on a server in your own network. It only connects outbound, so there is no inbound firewall rule to open and no VPN to set up.
Is the integration secure, and can we prove it afterwards?
Joinly is ISO27001-certified. Every change is recorded, so per employee you can look back at which access was granted when, on the basis of which role, and when it was revoked again. That is precisely what an auditor or a NIS2 assessment asks of you.
What does this integration cost?
The integration is part of the subscription — you pay per account per month, not per connector or per target system. The pricing page shows what the plans cost and what each one includes.
More about HR2Day
HR2day koppeling via Joinly: Slim en veilig gebruikersbeheer
Veel organisaties gebruiken HR2day als centraal HR- en salarissysteem. Het bevat alle actuele gegevens van medewerkers – van contracten en functies tot afdelingen en mutaties. Maar zolang HR2day niet gekoppeld is aan je IT-omgeving, blijft gebruikersbeheer een handmatig en foutgevoelig proces.
Waarom handmatig gebruikersbeheer met HR2day niet meer werkt
Zonder koppeling tussen HR2day en je applicaties lopen HR en IT vaak tegen dezelfde problemen aan:
IT moet accounts handmatig aanmaken of beheren via Excel, e-mail of losse lijsten
Nieuwe medewerkers wachten onnodig op toegang tot hun systemen en applicaties
Accounts van vertrokken medewerkers blijven te lang actief, met beveiligingsrisico’s tot gevolg
HR en IT werken langs elkaar heen, waardoor inconsistentie en frustratie ontstaan
Het resultaat: hogere werkdruk, meer kans op datalekken en vertraging bij onboarding.
De oplossing: automatische koppeling van HR2day met Joinly
Met Joinly koppel je HR2day direct aan je bedrijfsapplicaties en IT-systemen. Onze standaard HR2day koppeling automatiseert het volledige proces van user provisioning en deprovisioning. HR wordt leidend, terwijl IT alleen nog hoeft te controleren in plaats van uit te voeren.
Dit levert de HR2day koppeling op:
Nieuwe medewerkers krijgen automatisch toegang tot de juiste applicaties
Wijzigingen in functie, afdeling of contract worden direct doorgevoerd
Accounts worden veilig gedeactiveerd zodra iemand uit dienst treedt
HR en IT werken vanuit één betrouwbare bron van waarheid
Dankzij de koppeling ontstaat er een gestroomlijnde HR-IT keten: veiliger, efficiënter en zonder handmatige acties. Het resultaat: minder risico’s, lagere werkdruk en een veel snellere onboarding.
Op zoek naar een HR2day koppeling die veilig, betrouwbaar en toekomstbestendig is? Met Joinly wordt gebruikersbeheer eenvoudig, foutloos en volledig geautomatiseerd.
Where to go next

Everything about the HR2Day integration
Which data Joinly takes out of HR2Day, how often that happens and which other systems it goes on to.
See the HR2Day integration
Connect HR2Day to Microsoft Entra ID
The same source in HR2Day, with Microsoft Entra ID as the destination. If you run hybrid, one source feeds both.
See the Microsoft Entra ID integration
Further reading
Waarom wordt Identity en Access Management steeds belangrijker in het onderwijs, en wat automatiseer je het beste eerst?
Identity en Access Management wordt belangrijker omdat onderwijsinstellingen steeds meer systemen gebruiken, terwijl de digitale dreiging toeneemt en de eisen rond toegangsbeheer strenger worden. Het account van een medewerker is vaak de toegangsdeur tot gevoelige data, dus tijdige toekenning en intrekking van rechten zijn cruciaal. Begin met automatiseren waar het risico en de werklast het grootst zijn: het aanmaken, wijzigen en intrekken van medewerkersaccounts vanuit het personeelssysteem.
Wat vraagt het toetsingskader van SURFaudit op het gebied van toegangsbeheer voor medewerkers, en hoe automatiseer je dat?
Het toetsingskader van SURFaudit verlangt dat een instelling toegang van medewerkers gestructureerd toekent, wijzigt en intrekt, en dat aantoonbaar kan maken. Toegangsrechten mogen niet ruimer zijn dan nodig en moeten worden aangepast of ingetrokken zodra het dienstverband verandert of eindigt. Om volwassenheidsniveau 3 te halen, moet dit proces gedocumenteerd, formeel en aantoonbaar zijn. Automatisering vanuit het personeelssysteem maakt precies dat mogelijk.
How do I automatically revoke accounts of departing employees?
Integrate your HR system with an orchestration layer that runs on top of Microsoft Entra ID or Google Workspace. As soon as an employee-status is set to inactive in the HR system, this layer disables the account, revokes access rights, and logs every step. This ensures offboarding occurs automatically on the correct date, without manual ICT department action required.
Volwassenheidsniveau 3 bereiken voor toegangsbeheer
Zowel het Normenkader IBP (funderend onderwijs) als het toetsingskader van SURFaudit (mbo en hoger onderwijs) hanteren volwassenheidsniveau 3 als streefniveau. Voor toegangsbeheer betekent niveau 3: het beleid is vastgelegd, de uitvoering is geautomatiseerd en consistent, en je kunt aantonen dat het werkt. Geautomatiseerde provisioning vanuit het personeelssysteem brengt je daar het snelst.
Normenkader IBP of Cyberbeveiligingswet: wat is het verschil?
Het Normenkader IBP is de afgesproken norm voor digitale veiligheid in het funderend onderwijs (po en vo), met een zelfevaluatie vanaf 2027. De Cyberbeveiligingswet is echte wetgeving, de Nederlandse uitwerking van de Europese richtlijn NIS2, en geldt onder meer voor hbo en wo. Beide leggen veel nadruk op toegangsbeheer, maar ze verschillen in status, doelgroep en tijdlijn.
Browsing is free
Schedule a demo
In 30 minutes, we would love to show you how Joinly adds value to the entire organisation.
Schedule a demo