Sector solution · Education & childcare
IAM in education
In education, you manage two worlds simultaneously: employees and students, spread across all your schools. Joinly integrates your student administration system and HR with Microsoft 365 or Google Workspace. Ensuring that accounts and access are managed automatically, privacy-compliant, and demonstrably secure. Ready for the standard frameworks in education.
Take the IAM quick scan

Who is this for?
Joinly works for every educational organisation that wants to manage employee account management centrally and securely, while maintaining autonomy per school or location.

Primary education
School boards with dozens of schools and hundreds of employees, often working across multiple locations, working on the IBP standards framework.
IAM Primary Education
Secondary education
Schools with large, fluctuating teams of teachers and support staff, falling under the same IBP standards framework.
IAM Secondary education
MBO and higher education
Institutions in secondary vocational education, universities of applied sciences, and research universities that assess via SURFaudit; for colleges and universities, the Cybersecurity Act (NIS2) will also apply.
IAM secondary vocational and higher education
Childcare and children's centres
Integrated child centres (ICCs) that combine education and childcare, with mixed teams of teachers and pedagogical employees.
IAM Kinderopvang
What is IAM in education?
More and more schools are facing the same challenge: you need to work digitally secure, but no one knows exactly if it is "good enough".
Identity and Access Management (IAM) is the set of processes that manages who has access to which systems, and why. In education, this is challenging because staff work across many schools, often at multiple locations simultaneously, and because the inflow and outflow are continuous.
Properly managed IAM means that creating, modifying and revoking accounts is automatic and auditable.
Why IAM is essential for education
Education relies on trust and careful handling of data, with IAM at its core.

Strong access security
With smart access rules and strong authentication, you prevent unauthorized access to sensitive systems and data.

Least privilege access
Employees only receive the permissions they actually need for their role and school.

Automated lifecycle management
Accounts are created, updated, and deactivated with every personnel change, including for substitutes and employees at multiple schools, without manual work.

Demonstrably in control
Logging and reporting show who had access, when, and why, which is essential for accountability and audits.
Ready for 2027
IAM is an integral part of the educational standards frameworks
Digitale veiligheid is in het onderwijs geen vrijblijvende keuze meer. In de normenkaders voor de sector is toegangsbeheer een apart domein, en goed geregelde IAM is precies wat ervoor nodig is.

Primary and secondary education
The Information Security and Privacy Reference Framework (IBP) for Primary and Secondary Education, developed by Kennisnet and SIVON, comprises 69 information security standards and 25 privacy standards, divided across 15 domains. Identity and Access Management is one of them. By 1 January 2027, every school board must know their current status via a self-assessment and have an action plan in place; the goal is to reach maturity level 3 by 2030. The Ministry of Education, Culture and Science (OCW) expects insight into digital security as early as 2026.

MBO and higher education
Secondary vocational (Mbo), higher professional (hbo) and university (wo) education institutions assess their information security via the SURFaudit framework, aiming for maturity level 3. For hbo and wo, the Cybersecurity Act (the Dutch implementation of the European NIS2 directive) adds ten due diligence measures. The law is expected to take effect in 2026, with a transitional period of several years.
With automated provisioning, least privilege, logging, and demonstrable reporting, Joinly covers the access control standards of these frameworks.
How Joinly helps
Joinly works as a control and automation layer on top of Microsoft Entra ID or Google Workspace, powered by your HR system.
HR-driven provisioning
Wij koppelen je personeelssysteem aan de werkomgeving, zodat:
- accounts are automatically created upon onboarding
- access is immediately blocked upon offboarding
- a change in role automatically leads to the correct access
Role and access governance
Roles linked to job title and to school or location
- teacher, internal coordinator, caretaker and headteacher each have the correct profile
- transparent translation from role to permissions
Logging & Compliance reporting
we collect and structure provisioning logs, audit trails and exception reports
- access and changes are transparent for audits and incident response
- compliance with the standards framework is demonstrable
SCIM & application integrations
employees automatically provisioned to education and business operations applications
- no silos outside the central working environment
- complete control over access
Where schools often get stuck
Manual account creation and offboarding, done slightly differently for each school.
No central role structure (RBAC); fragmented management, leaving the board without an overview.
Limited capabilities to log and account for access.
Standalone applications without integration with HR or the authorisation process.

What you achieve with well-managed IAM
Prepare your educational organisation for secure access, reduced administrative burden, and smooth audits.
Ready for the standards framework:
Your IAM is configured to meet the requirements of the IBP Standards Framework and SURFaudit, meaning self-evaluations and audits require less time and fewer corrective actions.
Reduced administrative burden:
Administrators and the management office save time as onboarding, changes, and offboarding are processed automatically.
Automated lifecycle management:
Onboarding, role changes and offboarding are automatically processed in the workspace and integrated applications, without manual actions.
Secure and with no residual accounts:
No forgotten accounts of departed employees; access always reflects the actual situation at school.
IAM scan for education
In 30 minutes, we will show you how secure your account management currently is and identify the quickest wins.
Schedule a free IAM scan with our experts
Ask away
Frequently Asked Questions
If you're having trouble with the frequently asked questions, feel free to send us a message.
Frequently Asked Questions
Joinly focuses on employee account management from your HR system. Accounts for pupils and students are currently excluded; these remain within your own chain for students and learning materials.
With the systems commonly used in education, such as AFAS, Visma, and HR2day. The approach is system-agnostic: as long as your HR system makes changes available, Joinly can work with it.
Yes. Joinly works as a layer on top of Microsoft Entra ID or Google Workspace, and can also provision to a hybrid setup with a local Active Directory.
Yes. Access control is one of the 15 domains in the IBP Framework. Automated provisioning, least privilege, and logging demonstrably cover these standards, which is useful for the mandatory self-assessment from 2027 onwards.
The Cybersecurity Act, the Dutch implementation of the European NIS2 directive, places access management at the heart of its duty of care. Strong authentication, least privilege and logging are essential parts of this, which is exactly what Joinly automates.
Yes. The board centrally manages how accounts and access are created, while the school retains control over its own education. This is made possible by roles per school and location.
Joinly only shares the necessary data and logs every action. This ensures you operate according to data minimisation and can demonstrate that access is carefully managed.
Access is automatically blocked immediately, and accounts are cleared after a set period. This ensures no leftover accounts remain in your systems.
With a free IAM scan, we map out how secure your account management currently is and identify the quickest wins. After that, you decide the pace.
Knowledge Articles

Waarom wordt Identity en Access Management steeds belangrijker in het onderwijs, en wat automatiseer je het beste eerst?
Identity en Access Management wordt belangrijker omdat onderwijsinstellingen steeds meer systemen gebruiken, terwijl de digitale dreiging toeneemt en de eisen rond toegangsbeheer strenger worden. Het account van een medewerker is vaak de toegangsdeur tot gevoelige data, dus tijdige toekenning en intrekking van rechten zijn cruciaal. Begin met automatiseren waar het risico en de werklast het grootst zijn: het aanmaken, wijzigen en intrekken van medewerkersaccounts vanuit het personeelssysteem.
Marcel van Beek · 4 min leestijd

Wat vraagt het toetsingskader van SURFaudit op het gebied van toegangsbeheer voor medewerkers, en hoe automatiseer je dat?
Het toetsingskader van SURFaudit verlangt dat een instelling toegang van medewerkers gestructureerd toekent, wijzigt en intrekt, en dat aantoonbaar kan maken. Toegangsrechten mogen niet ruimer zijn dan nodig en moeten worden aangepast of ingetrokken zodra het dienstverband verandert of eindigt. Om volwassenheidsniveau 3 te halen, moet dit proces gedocumenteerd, formeel en aantoonbaar zijn. Automatisering vanuit het personeelssysteem maakt precies dat mogelijk.
Marcel van Beek · 3 min leestijd

Hoe houd ik accounts en toegang van medewerkers in de kinderopvang bij ondanks veel verloop en wisselende locaties?
Maak het personeelssysteem leidend en laat de accounts automatisch meebewegen. Begint, verandert of vertrekt een medewerker, dan past de toegang in de werkomgeving zich vanzelf aan. Zo blijven accounts kloppen ondanks veel verloop, invalkrachten en collega's die op meerdere locaties werken, en blijven er geen vergeten accounts achter.
Marcel van Beek · 3 min leestijd

Hoeveel tijd ben je kwijt aan het handmatig regelen van accounts, en hoe houd je daar tijd aan over?
Het handmatig aanmaken, wijzigen en intrekken van accounts kost de ICT afdeling structureel veel tijd, juist op de drukste momenten van het jaar. Door het personeelssysteem leidend te maken en de accounts automatisch te laten meebewegen, verdwijnt het meeste van dat herhaalwerk. De winst zit niet alleen in tijd, maar ook in minder fouten en minder vergeten accounts.
Marcel van Beek · 3 min leestijd

Hoe trek ik accounts van vertrekkende medewerkers automatisch in?
Koppel je personeelssysteem aan een orchestratielaag die boven Microsoft Entra ID of Google Workspace draait. Zodra een medewerker in het personeelssysteem op uit dienst staat, schakelt die laag het account uit, trekt de toegangsrechten in en legt elke stap vast. Zo gebeurt offboarding automatisch op de juiste datum, zonder handmatige actie van de ICT afdeling.
Marcel van Beek · 3 min leestijd

De zelfevaluatie van het Normenkader IBP voorbereiden (vóór 2027)
Vanaf 1 januari 2027 moet elk schoolbestuur in het funderend onderwijs via een zelfevaluatie weten waar het staat ten opzichte van het Normenkader IBP, en een plan van aanpak hebben om volwassenheidsniveau 3 te bereiken. Toegangsbeheer is een van de domeinen die je daarbij beoordeelt. Door dat nu te automatiseren, ga je de zelfevaluatie in met een sterk uitgangspunt en met bewijs bij de hand.
Marcel van Beek · 4 min leestijd

Volwassenheidsniveau 3 bereiken voor toegangsbeheer
Zowel het Normenkader IBP (funderend onderwijs) als het toetsingskader van SURFaudit (mbo en hoger onderwijs) hanteren volwassenheidsniveau 3 als streefniveau. Voor toegangsbeheer betekent niveau 3: het beleid is vastgelegd, de uitvoering is geautomatiseerd en consistent, en je kunt aantonen dat het werkt. Geautomatiseerde provisioning vanuit het personeelssysteem brengt je daar het snelst.
Marcel van Beek · 3 min leestijd

Normenkader IBP of Cyberbeveiligingswet: wat is het verschil?
Het Normenkader IBP is de afgesproken norm voor digitale veiligheid in het funderend onderwijs (po en vo), met een zelfevaluatie vanaf 2027. De Cyberbeveiligingswet is echte wetgeving, de Nederlandse uitwerking van de Europese richtlijn NIS2, en geldt onder meer voor hbo en wo. Beide leggen veel nadruk op toegangsbeheer, maar ze verschillen in status, doelgroep en tijdlijn.
Marcel van Beek · 4 min leestijd

Je personeelssysteem koppelen aan Microsoft 365 of Entra ID: AFAS, Visma of HR2day
In het onderwijs zijn AFAS, Visma (Visma.net HRM, de opvolger van Youforce) en HR2day de meest gebruikte personeels- en salarissystemen. Geen van deze maakt zelf accounts aan in Microsoft 365 of Google Workspace. Een orchestratielaag tussen je personeelssysteem en de werkomgeving vertaalt elke personeelsmutatie automatisch naar het juiste account met de juiste toegang.
Marcel van Beek · 4 min leestijd

Onboarding en offboarding van medewerkers in het onderwijs automatiseren
In het onderwijs wisselt personeel continu, met veel invallers en mensen die op meerdere scholen werken. Wordt offboarding niet net zo zorgvuldig geautomatiseerd als onboarding, dan blijven accounts achter in Microsoft 365, het netwerk en losse applicaties. Door beide vanuit het personeelssysteem te automatiseren, met eerst uitschakelen en daarna opruimen, voorkom je achtergebleven accounts en voldoe je aantoonbaar aan de normen.
Marcel van Beek · 4 min leestijd

Wat vraagt het Normenkader IBP op het gebied van toegangsbeheer?
Identity en Access Management is een van de 15 domeinen in het Normenkader Informatiebeveiliging en Privacy voor het Funderend Onderwijs (IBP). Concreet vraagt het kader om sterke authenticatie, toegang volgens least privilege, geautomatiseerd beheer van de levenscyclus van accounts en aantoonbare logging. Wie dat vanuit het personeelssysteem automatiseert, dekt deze normen in één keer af.
Marcel van Beek · 4 min leestijd


