When someone joins, moves or leaves in Buddee, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Buddee to Microsoft Entra ID, Joinly reads each HR change through the Buddee REST API at the source and applies it automatically to the right account. Buddee stays your source of truth for people and contracts; Joinly is the engine that turns each employee and employment change into an accurate, traceable identity action.
Key takeaways
Buddee stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically from the Buddee API.
Joinly maps Buddee’s structure — department, team and job title (functie) — to the right Entra ID groups and licences, logic Buddee has no native concept of.
Joinly reads the active employment and employment terms, so the real contract start and end dates drive account creation and disabling, not the moment HR opened the record.
SSO alone (Microsoft or Google) only authenticates existing users; Joinly does the actual provisioning — creating, updating and disabling accounts — that Buddee cannot do on its own.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001, and hosted on EU infrastructure.
Quick facts
Source system | Buddee (HR & payroll platform) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Buddee REST API (with webhooks where available) → Entra ID |
Supported events | Joiner, mover, leaver (incl. contract changes and rehire) |
Synced attributes | Name, email / UPN, department, team, job title, manager, contract start and end date |
Authentication | OAuth / JWT tokens against the Buddee API (per-tenant credentials) |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Buddee to Microsoft Entra ID?
Joinly reads each HR change in Buddee through its REST API — using webhooks where available and a frequent scheduled read otherwise — and applies it to the matching Entra ID account automatically. Buddee holds the authoritative employee and employment record, so it is the starting point for every identity action.
Joiner. HR completes the hire in Buddee. Joinly reads the new employee and their active employment — including department, team, job title and the employment terms — and determines the role from those attributes. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups, timed to the real contract start date.
Mover. When someone changes team, department or role in Buddee, or their contract is updated, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual job.
Leaver. On the contract end date recorded in Buddee, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and a soft-delete grace window can retire the account safely a set number of days later.
Example: A restaurant group runs Buddee for its HR and payroll and hires a new shift manager with a contract starting next Monday. Joinly reads the employment record, waits until the start date, creates the Entra ID account, assigns a Microsoft 365 licence and adds the manager to the Venue-A and Shift-Leads groups. When that person later moves to a second venue, Joinly swaps the venue group the same day while keeping a single, stable account.
What manual user management costs
Without automation, every account starts as a message from HR or a line in a Buddee export that IT works through by hand. Buddee’s Microsoft and Google SSO make sign-in smooth, but they only authenticate accounts that already exist — creating, changing and disabling those accounts is still a manual job, or a script someone has to build and maintain against the API.
Onboarding delays. New joiners wait for accounts, licences and group access while a request sits in a queue, losing productive days in their first week — painful in shift-based teams where day one is a working shift.
Permissions that don’t keep up (privilege creep). When movers change team or role in Buddee, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — easy to miss when a contract simply ends in Buddee and nobody tells IT.
Joinly vs. a self-built Buddee API integration
Buddee gives you a REST API, webhooks and SSO, but no identity provisioning of its own. The realistic alternative is scripting the API yourself or relying on SSO alone. Here’s how that compares to Joinly.
Joinly | Self-built API script / SSO only | |
|---|---|---|
Source | Reads the Buddee API directly (employee + active employment) | You call and maintain the API yourself, or SSO reads nothing at all |
Role-to-group mapping | Built in, rule-based on department, team and job title | You code and maintain every rule; SSO has none |
Contract dates / future hires | Times account creation and disabling to the employment dates | Custom date logic to build and test |
Licence assignment | Driven by role / attributes | Manual or scripted by hand |
On-premise AD | Yes, own agent plus the native Microsoft agent | Another integration to build and run |
Audit trail | Per-action logging tied to the Buddee change | Whatever you build; SSO logs sign-ins only |
Maintenance | Joinly maintains the connector as the API evolves | Your problem when Buddee changes the API |
Watch-outs when connecting Buddee to Microsoft Entra ID
A few Buddee-specific details decide whether this connection stays reliable at scale.
Read the employment, not just the employee. In Buddee the definitive contract dates and hours live on the active employment and its employment terms, not only on the employee record. Joinly reads the active employment so the real start and end dates drive provisioning, rather than the day someone was first entered.
No native identity logic. Buddee is HR and payroll; it has no concept of a UPN, a unique login or Entra groups. Joinly adds explicit rules that turn department, team and job title into the correct groups and licences, so role drives access instead of manual assignment.
SSO is not provisioning. Microsoft and Google SSO let existing users sign in, but they never create or disable an account. Joinly handles the actual lifecycle, so accounts appear and disappear in step with the Buddee record.
UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, location code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Confirm the API scope up front. Buddee’s developer documentation is lean in places, so Joinly confirms the exact objects, fields and webhook events available on your tenant with Buddee support before go-live, and maps only what is verified.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Buddee change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a hospitality group running around fifteen restaurants on Buddee, with roughly 900 employees and constant churn — seasonal hires, students, people moving between venues every few weeks. Buddee keeps HR and payroll tidy, but every new colleague still means someone in the small IT team creating a Microsoft account by hand, guessing which groups they need, and hoping the leaver list is up to date. New starters routinely work their first shift without a working login, and old accounts linger long after a contract has ended.
Connect Buddee to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change in Buddee at the source and acts on it automatically: new hires have their account, Microsoft 365 licence and group access ready on their contract start date, a move to another venue swaps the right groups the same day, and leavers are disabled on their contract end date with a 30-day soft-delete grace window.
“Our people start on a shift, not on a Monday at nine, so an account that isn’t ready is a real problem. Now it’s simply there when they arrive, and when a contract ends the account goes quiet on its own.” — Head of IT, restaurant group
The outcome this setup is designed for: onboarding drops from a manual queue to zero touch, stale accounts after busy seasons disappear, and the team can show exactly which Buddee change created every bit of access.
More than a connector
A standalone Buddee to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Buddee to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the Buddee integration in the Joinly marketplace
Open the Joinly marketplace and search for the Buddee integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Buddee integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Buddee connection details: the API endpoint (api.buddee.nl) and the OAuth / token credentials for your tenant. We only ask for the information needed to establish a successful connection with Buddee, and we confirm the exact scope with Buddee support where the documentation is thin. All data is encrypted and stored securely.

Enter your Buddee API endpoint and credentials in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Buddee employee and employment fields.
Frequently asked questions
How do I map the manager? Reference the manager on the Buddee employee record and Joinly resolves the link to the right manager automatically.
Which record drives the dates? Map from the active employment and its employment terms, so the real contract start and end dates drive provisioning.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map Buddee fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Buddee should run. Where webhooks are available on your tenant, changes can flow through even faster.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Buddee flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the contract end date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Buddee to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Buddee to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, and where webhooks are available on your Buddee tenant changes can flow through even faster, so updates reach Entra ID quickly without waiting for a nightly batch.
Isn’t Buddee’s Microsoft SSO enough?
SSO only lets an existing account sign in. It never creates, updates or disables an account. Joinly does the provisioning — the joiner, mover and leaver lifecycle — that SSO leaves untouched.
How does Joinly connect to Buddee?
Through Buddee’s REST API using OAuth / token credentials, reading each employee together with their active employment and employment terms. Where webhooks are available they are used to pick up changes; otherwise a frequent scheduled read keeps everything current.
Which attributes sync from Buddee to Entra ID?
Name, email / UPN, department, team, job title, manager, and contract start and end date. Additional fields available on your tenant can be mapped via Liquid templates.
Buddee’s API docs look limited — can you still connect it?
Yes. Joinly confirms the exact objects, fields and webhook events available on your tenant with Buddee support before go-live, and maps only what is verified, so the connection is built on what your account actually exposes.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Buddee to Active Directory guide.


