When someone joins, moves or leaves in BCS HR, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect BCS HR to Microsoft Entra ID, Joinly reads each HR change in BCS at the source — through the BCS RESTful Services API — and applies it automatically to the right account. BCS HR stays your source of truth; Joinly is the engine that keeps every action accurate and traceable, even when the same person holds more than one dienstverband.
Key takeaways
BCS HR stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically from the BCS RESTful Services API.
Joinly maps BCS structures — afdeling, kostenplaats, organisatie-eenheid and functie — to the right Entra ID groups and licences, which a plain attribute export can’t do on its own.
Joinly follows the dienstverband dates, so a flex or uitzend contract provisions on its actual start date and is disabled when it ends — not when HR happens to key the record.
Multiple concurrent dienstverbanden for one medewerker are resolved to a single, stable UPN, so a second placement adds access instead of creating a duplicate account.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001, from a Dutch/EU platform.
Quick facts
Source system | BCS HR (BCS HRM & Salaris) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | BCS RESTful Services API → Entra ID |
Supported events | Joiner, mover, leaver (incl. rehire, retroactive changes, multiple dienstverbanden) |
Synced attributes | Name, email / UPN, afdeling, functie, manager, kostenplaats, organisatie-eenheid, contract start and end date |
Authentication | Token-based credential over HTTPS (to be confirmed with your BCS environment) |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync BCS HR to Microsoft Entra ID?
Joinly reads each HR change in BCS HR through the RESTful Services API and applies it to the matching Entra ID account automatically. BCS holds the authoritative medewerker and dienstverband record, so it is the starting point for each identity action.
Joiner. HR completes the hire in BCS HR. Joinly reads the new medewerker and dienstverband, determines the role from attributes like afdeling, functie and kostenplaats, then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the contract start date rather than the moment the record was entered.
Mover. When someone changes functie, afdeling or organisatie-eenheid in BCS, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new role is revoked, so permissions stay aligned with the actual job.
Leaver. On the end date of the dienstverband recorded in BCS, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone leaves, and multiple dienstverbanden are taken into account, so access is only removed when the last active contract ends.
Example: A staffing agency hires a warehouse flex worker in BCS HR with a start date next Monday. Joinly reads the dienstverband, waits until the start date, creates the Entra ID account, assigns a lightweight licence and adds the worker to the correct client-site group. When that worker later picks up a second placement at another client, Joinly keeps one stable UPN and simply adds the extra group, so both assignments work without breaking sign-in.
What manual user management costs
Without automation, every account starts as a BCS ticket or a line in a spreadsheet that IT works through by hand. BCS can export employee data over its webservices or as a file, and you can build a custom job against the RESTful Services API, but a raw export moves attributes only — it doesn’t map roles to groups or reason about contract dates and multiple placements, so the part that actually decides access still falls to people.
Onboarding delays. New joiners wait for accounts, licences and group access while a ticket sits in a queue — painful in staffing, where a flex worker may only be on site for a few weeks.
Permissions that don’t keep up (privilege creep). When movers change functie or afdeling, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — and with multiple dienstverbanden it is easy to disable an account while another contract is still active.
Joinly vs. a custom BCS export / Entra Cloud Sync
BCS has no native provisioning to Entra ID, so the realistic alternative is a custom job on the BCS webservice or file export, or a generic attribute flow such as Entra Cloud Sync. Both move data; neither decides access. Here’s how they compare for a BCS-driven setup.
Joinly | Custom BCS export / Entra Cloud Sync | |
|---|---|---|
Source | Reads the BCS RESTful Services API directly | CSV / webservice export or a generic attribute source |
Role-to-group mapping | Built in, rule-based on afdeling, functie and kostenplaats | Not available; scripted by hand or out of scope |
Contract-dated / future hires | Times account creation to the dienstverband start date | Fires on the next run; no date awareness |
Multiple dienstverbanden | Resolves to one stable UPN across placements | Risk of duplicate accounts or premature disable |
Licence assignment | Driven by role / attributes | Manual or group-based only |
On-premise AD | Yes, own agent plus the native Microsoft agent | Separate tooling and scripting required |
Audit trail | Per-action logging tied to the HR source | Limited or home-grown |
Watch-outs when connecting BCS HR to Microsoft Entra ID
A few BCS-specific and staffing-specific details decide whether this connection stays reliable at scale.
Contract dates and high churn. In a flex or uitzend context, short dienstverbanden start and end constantly, and provisioning too early or too late both cause problems. Joinly reads the contract start and end dates and times account creation and disable to them, so access is ready on the right day and gone when the contract ends.
Multiple dienstverbanden per person. One medewerker can hold more than one active or sequential contract — for example a worker placed at two clients. A naive rule can create a duplicate account or disable sign-in while another contract is still live. Joinly applies explicit rules to keep one stable UPN and add access per placement.
Retroactive changes and rehires. BCS handles changes with terugwerkende kracht and frequent rehires. Joinly reconciles back-dated starts and re-activates the correct existing account on a rehire instead of spawning a new one.
Mapping BCS structures to Entra groups. Afdeling, kostenplaats, organisatie-eenheid and functie don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from those structures to the correct groups and licences, so role drives access rather than manual assignment.
UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, org-unit code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which BCS HR change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a staffing agency with around 3,500 active flex workers placed across dozens of client sites, running BCS HR for its personnel and payroll administration while its identity provisioning never quite keeps up. New placements start and end every week, workers often hold two dienstverbanden at once, and rehires are routine — so the IT team keys accounts by hand from a BCS export. New flex workers wait until day two or three for a login, and every so often an account is disabled while the person is still working a second placement.
Connect BCS HR to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change in BCS at the source and acts on it automatically: new placements have their account, licence and group access ready on the contract start date, a second placement just adds access under one stable UPN, transfers swap the right groups the same day, and leavers are disabled on the contract end date with a 30-day soft-delete grace window.
“Multiple contracts and constant rehires used to break every manual step. Now an account is simply ready on the start date, a second placement just adds access, and we can show exactly which BCS change created every bit of access.” — Head of IT, staffing agency
The outcome this setup is designed for: onboarding drops from days to zero touch, duplicate-account and premature-disable errors stop, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone BCS HR to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect BCS HR to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the BCS HR integration in the Joinly marketplace
Open the Joinly marketplace and search for the BCS HR integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the BCS HR integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your BCS HR connection details: your RESTful Services API endpoint and the API credential (token) for your BCS environment. We only ask for the information needed to establish a successful connection with BCS. All data is encrypted and stored securely.

Enter your BCS RESTful Services endpoint and API credential in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from BCS fields like afdeling, functie and kostenplaats.
Frequently asked questions
How do I map the manager? Reference the manager’s BCS identifier in the mapping and Joinly resolves the link to the right manager automatically.
How do I handle someone with two dienstverbanden? Pick the leading contract as the driver for the UPN; Joinly exposes the active dienstverbanden so you can choose the primary one.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map BCS fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from BCS HR should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in BCS flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the contract end date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting BCS HR to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the BCS HR to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in BCS HR reach Entra ID quickly without waiting for a nightly batch.
How does Joinly handle someone with more than one dienstverband?
Joinly reads all active contracts for a person and applies your rules to pick the leading dienstverband as the driver for the UPN, so a second placement adds access without creating a duplicate account or breaking sign-in.
How are contract start dates and rehires handled?
Joinly reads the dienstverband start and end dates and times account creation and disable to them, and on a rehire it re-activates the correct existing account instead of creating a new one — which matters in high-churn staffing environments.
Which attributes sync from BCS HR to Entra ID?
Name, email / UPN, afdeling, functie, manager, kostenplaats, organisatie-eenheid, and contract start and end date. Additional BCS fields can be mapped via Liquid templates.
How does Joinly connect to BCS HR?
Through the BCS RESTful Services API, using an API credential scoped to your BCS environment. Where a customer prefers a file-based webservice export, Joinly can work from that as well; the exact endpoint and authentication are confirmed with your BCS setup during onboarding.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the BCS HR to Active Directory guide.


