Sage HR · offboarding
Sage HR offboarding automation: close Entra ID and Active Directory accounts on the termination date
HR closes the file in Sage HR; three weeks later the account still signs in. That gap is what offboarding automation removes. Here is what Joinly does with a leaver from Sage HR, in order, and what stops it from doing the wrong thing.

Where the gap comes from
Sage HR knows the termination date before anyone else does. IT hears about it through a ticket, a mail or a monthly list — if at all. Every day in between, a former employee keeps a working account, a licence and whatever the account could reach. Manual offboarding is not unsafe because people are careless; it is unsafe because it depends on someone remembering to start it.
How Joinly closes a leaver from Sage HR
Joinly reads the termination date through the Sage HR REST API (frequent sync, multiple times per day) and schedules the leaver workflow for that date. On the day, the steps run in order, and each one waits for the previous one to succeed:
- Disable the account in Entra ID and revoke every active session, so an open laptop is signed out too.
- In on-premise Active Directory, the Joinly AD Agent disables the account and can move it to a disabled-users OU.
- Remove group memberships — and with them the access that hung off those groups — and return the Microsoft 365 licences.
- Set an out-of-office, clear the calendar and convert the mailbox to a shared mailbox so the team keeps the correspondence.
- Remove SharePoint permissions and Teams memberships; raise an incident in TOPdesk or a request in Freshservice for the hardware.
- Days or weeks later, a threshold workflow archives or deletes the account and the identity.
What stops it from closing the wrong account
Someone with two contracts in Sage HR is one person in Joinly, and the account is only disabled when the last active employment ends. Every import can run as a dry run first, with an Excel export of what would be deactivated. Thresholds cap how many deactivations one run may produce before it is blocked for approval, and an evaluation that would revoke more than 20% of assignments in one go stops itself — a broken HR export does not lock out half the organisation overnight.
Rehires and returning contractors
Sage HR reports rehires as such (joiner, mover, leaver (incl. rehire and team / position changes)). Joinly matches the returning person to the existing identity, re-enables the account instead of creating a second one, and applies the access of the new position — not the old one.
The evidence afterwards
Each step lands in the audit log with its source and the workflow that caused it: when the account was disabled, which groups and licences were removed, which ticket was raised. That is the answer to the auditor's question — not "we have a process", but the record of the process having run.
Frequently asked
Questions about Sage HR
Does the account close on the exact termination date in Sage HR?
Yes. Joinly schedules the leaver workflow on the date Sage HR reports and runs it that day. You can also add follow-up workflows that run a set number of days after the termination date — for the mailbox, the archive or the deletion.
What if HR enters the termination date late?
Then the workflow runs at the next import after the date is known. That is why the import cadence matters (frequent sync, multiple times per day) and why a threshold protects you: a late batch of terminations is visible before it is applied.
Can I keep the mailbox?
Yes. The workflow can convert it to a shared mailbox and delegate it to the manager, set an out-of-office and clear the calendar, so the correspondence stays and the sign-in does not.
Does this work for an on-premise Active Directory too?
Yes. The Joinly AD Agent disables the account, moves it to the OU you choose and removes group memberships, from inside your network over outbound HTTPS only.
Read next
Installation guides
About this HR system
See what Joinly can do for your organisation?
Start a free trial today or get in touch for advice on your HR and Microsoft environment.