Connect Cornerstone OnDemand to Microsoft Entra ID

Connect Cornerstone OnDemand to Microsoft Entra ID

Connect Cornerstone OnDemand to Microsoft Entra ID

When someone joins, moves or leaves in Cornerstone OnDemand, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Cornerstone OnDemand to Microsoft Entra ID, Joinly reads each change at the source — through the Cornerstone Edge API — and applies it automatically to the right account. Cornerstone stays your source of truth for talent data; Joinly is the engine that keeps every action accurate and traceable, and it pins down which identifier really drives the account.

Key takeaways

  • Cornerstone stays your source for the people it governs; Joinly applies every joiner, mover and leaver to Entra ID automatically.

  • Joinly maps Cornerstone Organizational Units — Division, Position, Location, Cost Center and Grade — to the right Entra ID groups and licences, work the deprecated native Entra provisioning app never did reliably.

  • Cornerstone’s userId, username and SSO subject are three different identifiers; Joinly maintains the cross-system mapping so it never acts on a stale or mismatched record.

  • Because Cornerstone is talent/learning-first and often not the HRIS of record, Joinly lets you set exactly which feed is authoritative for each attribute, so its OU data doesn’t silently overwrite better data.

  • Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.

Cornerstone OnDemand

Joiner

Mover

Leaver

Microsoft Entra ID (formerly Azure AD)

Quick facts

Source system

Cornerstone OnDemand (CSX / Organizational Units)

Target system

Microsoft Entra ID (formerly Azure AD)

Connection method

Cornerstone Edge API (REST) → Entra ID

Supported events

Joiner, mover, leaver (incl. rehire, OU transfer, status change)

Synced attributes

Name, email / UPN, division, position, manager, location, cost center, grade, start and end date

Authentication

OAuth 2.0 (scoped Edge API app + bound security permission)

Real-time or batch

Frequent sync, multiple times per day

Compliance

ISO 27001, NIS2-ready, GDPR (EU data centre)

How does Joinly sync Cornerstone OnDemand to Microsoft Entra ID?

Joinly reads each change in Cornerstone through the Edge API and applies it to the matching Entra ID account automatically. Cornerstone holds the talent record and its OU structure; Joinly resolves the right person, then acts on the right account.

  1. Joiner. A new user appears in Cornerstone with their Organizational Units set. Joinly reads the record through the Edge API, determines the role from Division, Position and Cost Center, and creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the start date and bound to the stable userId rather than a username that may change.

  2. Mover. When someone changes Position, Division or Location in Cornerstone, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new OU placement is revoked, so permissions stay aligned with the actual role.

  3. Leaver. When a user’s status moves to inactive or terminated in Cornerstone — or their end date passes — Joinly disables the Entra ID account automatically. No orphaned accounts are left active, and the matching is done on the internal Cornerstone ID, so a recycled username never disables the wrong person.

Example: A university hires a research administrator in Cornerstone, placed in the Division ‘Faculty of Science’ and Position ‘Grant Coordinator’, with a start date next Monday. Joinly reads the record, waits until the start date, creates the Entra ID account, assigns an Office E3 licence and adds the coordinator to the SCI-Research group. When that person later transfers to the Position ‘Department Manager’, Joinly swaps the groups the same day — matching on the unchanged Cornerstone userId, not the email address that the move also rewrote.

What manual user management costs

Without automation, every account starts as a Cornerstone export or a line in a spreadsheet that IT works through by hand. The native Entra provisioning app for Cornerstone has been deprecated and Cornerstone retired its Entra SCIM path, so there is no supported out-of-the-box bridge left — what remains is the SFTP Data Feed, a third-party connector or manual effort, and none of those decide access for you.

  • Onboarding delays. New joiners wait for accounts, licences and group access while a ticket sits in a queue, losing productive days in their first week.

  • Permissions that don’t keep up (privilege creep). When movers change Position or Division, old access often stays attached, so people accumulate rights they no longer need.

  • Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — and a username-based match can miss the right account entirely when an ID was recycled.

Joinly vs. the native Cornerstone provisioning options

The native Entra provisioning app for Cornerstone is deprecated and Cornerstone’s own Entra SCIM connector is gone, so the realistic alternatives are the SFTP Data Feed or a third-party connector. Here’s how that compares with Joinly for a Cornerstone-driven setup.


Joinly

SFTP Data Feed / connector / manual

Source

Reads the Cornerstone Edge API directly

Flat-file export or generic connector

OU-to-group mapping

Built in, rule-based on Division / Position / Cost Center

Manual mapping; no role-to-group out of the box

Identifier handling

Maps userId, username and SSO subject explicitly

Often keys on username — drifts when it changes

Source-of-truth control

Pick the authoritative feed per attribute

Cornerstone OU data can overwrite better data

Native Entra provisioning

Not needed — deprecated by Microsoft and Cornerstone

No supported native path remains

Licence assignment

Driven by role / OU attributes

Manual or group-based only

Audit trail

Per-action logging tied to the HR source

Limited

Watch-outs when connecting Cornerstone OnDemand to Microsoft Entra ID

A few Cornerstone-specific details decide whether this connection stays reliable at scale.

  • Three identifiers that don’t auto-map. Cornerstone’s internal userId, the login username and the SSO subject are three separate things, and none derives from the others. Match on the wrong one and you update or disable the wrong account. Joinly keys on the stable userId and maintains the cross-system mapping, so a renamed username never breaks the link.

  • Cornerstone may not be your source of truth. Cornerstone is talent/learning-first, and its OU data is itself usually fed from an upstream HRIS. Joinly lets you set which feed is authoritative per attribute, so weaker Cornerstone OU values don’t silently overwrite better data from a core HR system.

  • Mapping Organizational Units to Entra groups. Division, Position, Location, Cost Center and Grade don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from those OUs to the correct groups and licences, so role drives access rather than manual assignment.

  • Reporting API lag and rate limits. The Reporting API reads the real-time data warehouse with a roughly 15-minute refresh, and high-volume reads are rate-limited. Joinly schedules reads sensibly and reconciles against the transactional API so a change isn’t missed or double-applied.

  • UPN format with duplicate names. When two users share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, location code or controlled tiebreaker — so every UPN is unique and predictable from day one.

Joinly handles each of these by default with custom mapping and transformation.

Always audit-ready

Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Cornerstone change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.

Example case

Picture a university with around 9,000 staff and a large pool of seasonal teaching and research contracts, running Cornerstone OnDemand for learning and talent while its identity provisioning never quite keeps up. The old native Cornerstone-to-Entra app is gone, so accounts are created from a spreadsheet export — and because Cornerstone usernames get recycled and rewritten on transfers, the wrong account occasionally gets disabled when someone simply changes faculty.

Connect Cornerstone OnDemand to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each change in Cornerstone at the source, matches on the stable internal userId, and acts on it automatically: new hires have their account, Office licence and group access ready on their start date, transfers between Divisions swap the right groups the same day, and leavers are disabled on their end date with a 30-day soft-delete grace window.

“Recycled usernames used to be the thing that broke every sync — we once disabled an active professor by accident. Now Joinly keys on the Cornerstone ID, an account is simply ready on the start date, and we can show the auditor exactly which change created every bit of access.” — Head of IT, university

The outcome this setup is designed for: onboarding drops from days to zero touch, mismatched-identifier errors stop entirely, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.

More than a connector

A standalone Cornerstone to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.

Schedule a demo

Installation manual

Installation manual

Connect Cornerstone OnDemand to Microsoft Entra ID

Connect Cornerstone OnDemand to Microsoft Entra ID

Installation guide

Follow these steps to connect Cornerstone OnDemand to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.

1. Create your account

Go to platform.joinly.app and create your account.

Note: charges may apply for using the platform after the trial period ends.


Joinly account creation screen at platform.joinly.app


Sign up at platform.joinly.app to get started.

2. Connect your Microsoft account

Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.


Joinly identity provider setup screen for connecting a Microsoft Entra tenant


Connect your Microsoft tenant and pick your scopes.

3. Import your existing accounts from Entra ID

Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.

4. Find the Cornerstone integration in the Joinly marketplace

Open the Joinly marketplace and search for the Cornerstone OnDemand integration.

Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.


Joinly marketplace showing available HR integrations


Search the marketplace for the Cornerstone OnDemand integration.

5. Follow the installation wizard

You may be redirected to integrations.joinly.app. Create an account there and enter your Cornerstone connection details: your portal (corp) URL, and the OAuth 2.0 Edge API credentials (client ID and secret) with the right scopes. Make sure the Cornerstone API and Reporting API are enabled under Admin > Tools > Edge > Integrations > Manage APIs. We only ask for the information needed to establish a successful connection with Cornerstone. All data is encrypted and stored securely.


Joinly installation wizard for entering Cornerstone OnDemand connection details


Enter your Cornerstone portal URL and OAuth Edge API credentials in the wizard.

6. Configure your field mapping

Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Cornerstone fields.

Frequently asked questions

  • How do I map the manager? Reference the manager’s Cornerstone user identifier in the mapping and Joinly resolves the link to the right manager automatically.

  • Which identifier should I match on? Use the internal Cornerstone userId as the stable key, not the username, so renames and recycled logins never break the match.

  • How do I prevent duplicate usernames? Use the generateUniqueUsername helper, which falls back to the next pattern when the first one is already taken:
    {{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}


Joinly field mapping screen for Cornerstone attributes using Liquid templates


Map Cornerstone OU fields to Entra ID attributes with Liquid templates.

7. Configure the scheduled import

At platform.joinly.app/settings/import-configs, configure how often the import from Cornerstone should run.

8. Configure your workflows

Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Cornerstone flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the end date (for example 30 days) to retire accounts safely.


Joinly workflow editor creating an employee onboarding workflow


Create a trigger-based onboarding workflow.


Adding the create or update employee in Entra action to a workflow


Add the create/update action, then set your matching strategy and field mapping.


Adding the Entra soft delete action to remove accounts on employee leave


Add the Entra soft delete action to retire accounts safely.

## AD on-premise support

Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Cornerstone OnDemand to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.

Frequently asked questions

Does the Cornerstone OnDemand to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Cornerstone reach Entra ID quickly without waiting for a nightly batch. Joinly accounts for the Reporting API’s roughly 15-minute data-warehouse refresh so nothing is missed.

Which Cornerstone identifier does Joinly match on?
The stable internal userId. Cornerstone’s userId, username and SSO subject are three separate identifiers that don’t map to each other automatically, so Joinly keys on the userId and maintains the cross-system mapping — a renamed or recycled username never disables the wrong account.

What if Cornerstone isn’t our HRIS source of truth?
That’s common — Cornerstone is talent/learning-first and its OU data is often fed from an upstream HRIS. Joinly lets you set which feed is authoritative per attribute, so Cornerstone values only drive the attributes you trust them for.

Which attributes sync from Cornerstone to Entra ID?
Name, email / UPN, division, position, manager, location, cost center, grade, and start and end date. Custom Cornerstone fields can be mapped via Liquid templates.

Do I still need the native Entra provisioning app for Cornerstone?
No — and you couldn’t anyway. Microsoft deprecated the gallery provisioning app for Cornerstone and Cornerstone retired its Entra SCIM path. Joinly takes over the provisioning, OU-to-group mapping and identifier handling, and maintains it as your Cornerstone data changes.

Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Cornerstone OnDemand to Active Directory guide.

Request installation support