Skip to main content
Joinly by KoppelHet

Multi-tenant

Multi-tenant identity management: all your clients from one login

You probably have tenant management sorted already. What most MSPs do not do from one place is keep track of who should have an account at each client. That is where Joinly sits alongside your existing tooling.

The short answer

Multi-tenant identity management means an MSP manages the identities of several clients from one place, while each client stays separate. In Joinly each client has its own environment with its own integrations, roles and audit log, and as a partner you switch between your clients from one login. Joinly works alongside Microsoft 365 Lighthouse and GDAP: they handle your access to your clients' tenants, and Joinly handles who should have an account within each tenant.

What tenant management covers, and what it leaves open

According to Microsoft, Microsoft 365 Lighthouse is meant to help MSPs serve their customers "at scale from a single portal", with security baselines, an overview across all tenants, device compliance and common tasks such as resetting a password. It is available to partners in the Cloud Solution Provider programme. With GDAP you give your engineers scoped admin roles in your clients' tenants.

That covers how you get into your clients' environments and how their tenants are set up. What it does not know is that someone starts in the finance team on Monday, that someone changed role last week or that someone leaves on Friday. That information lives in your client's HR system, and that is where Joinly starts.

Every client gets its own environment

In Joinly each client has its own environment. It holds the integrations with that client's HR system and Microsoft tenant, with separate credentials per integration, that client's roles and workflows and its own audit log. What happens at one client is never seen or touched by another.

Joinly creates its own connection with each tenant, with defined permissions that your client approves in their own environment. That connection is separate from your GDAP relationship, so a change in your partner access does not affect your client's lifecycle.

Per client you switch on what that client needs. One client runs only the lifecycle from HR, another also uses roles, segregation of duties and access requests.

One login, and an overview per client

You and your engineers switch between the clients you manage from one login, with an overview per client of what is running and what has happened. Your client can look in too, each with their own view: HR sees the employee data, IT the technical side and a manager their own team.

For anything you want to show in your own portal or PSA, there is the API. It uses keys per client, and for each key you decide what it may do.

Het Entra ID-beheer in Joinly: gasten, MFA-reset, TAP en sessies

Who handles what

Tenant management and Joinly side by side, for the tasks that come back most often at an MSP.

Your engineers' access to your client's tenant
Tenant management (Lighthouse, GDAP): Yes, with scoped GDAP roles
Joinly: Its own connection per client, separate from GDAP
Security baselines and device compliance
Tenant management (Lighthouse, GDAP): Yes
Joinly: Belongs to tenant management
Reset a password, set up MFA again
Tenant management (Lighthouse, GDAP): Yes
Joinly: Yes, including an MFA reset and a Temporary Access Pass
Create an account when someone joins
Tenant management (Lighthouse, GDAP): Manually or with your own script
Joinly: Automatically from HR
Adjust access after a change of role
Tenant management (Lighthouse, GDAP): Manually
Joinly: Automatically, based on roles
Close the account when someone leaves
Tenant management (Lighthouse, GDAP): When the ticket arrives
Joinly: On the last day, from HR
Why a change was made
Tenant management (Lighthouse, GDAP): Audit logs per tenant
Joinly: Per client, with the source: HR, workflow, administrator or API

Multi-tenant

Frequently asked questions

  • Is Joinly multi-tenant?

    Yes. Each client has its own, strictly separated environment with its own integrations, roles and audit log, and as a partner you switch between your clients from one login.

  • Do I need GDAP to use Joinly?

    No. Joinly creates its own connection with each tenant with defined permissions, which your client approves in their own environment. You use your GDAP relationship for your own admin tasks.

  • Does Joinly replace Microsoft 365 Lighthouse?

    No. Lighthouse is about managing and securing tenants and devices. Joinly is about the lifecycle of identities based on HR. You use them side by side.

  • Can one client see anything of another?

    No. Each client has its own environment with its own data, integrations and audit log. Only you as the partner can switch between the environments.

  • Can I switch on different features per client?

    Yes. Per client you switch on the features that client needs, and you can upgrade per client at any time, keeping the setup in place.

Account management for your clients as a standard service?

In an introduction we walk through how Joinly would work for your clients: which HR systems, which environments and where you want to start. We agree the terms of a partnership in the same conversation.

Book an introduction