When someone joins, moves or leaves in Cornerstone OnDemand, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Cornerstone OnDemand to Microsoft Entra ID, Joinly reads each change at the source — through the Cornerstone Edge API — and applies it automatically to the right account. Cornerstone stays your source of truth for talent data; Joinly is the engine that keeps every action accurate and traceable, and it pins down which identifier really drives the account.
Key takeaways
Cornerstone stays your source for the people it governs; Joinly applies every joiner, mover and leaver to Entra ID automatically.
Joinly maps Cornerstone Organizational Units — Division, Position, Location, Cost Center and Grade — to the right Entra ID groups and licences, work the deprecated native Entra provisioning app never did reliably.
Cornerstone’s userId, username and SSO subject are three different identifiers; Joinly maintains the cross-system mapping so it never acts on a stale or mismatched record.
Because Cornerstone is talent/learning-first and often not the HRIS of record, Joinly lets you set exactly which feed is authoritative for each attribute, so its OU data doesn’t silently overwrite better data.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | Cornerstone OnDemand (CSX / Organizational Units) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Cornerstone Edge API (REST) → Entra ID |
Supported events | Joiner, mover, leaver (incl. rehire, OU transfer, status change) |
Synced attributes | Name, email / UPN, division, position, manager, location, cost center, grade, start and end date |
Authentication | OAuth 2.0 (scoped Edge API app + bound security permission) |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Cornerstone OnDemand to Microsoft Entra ID?
Joinly reads each change in Cornerstone through the Edge API and applies it to the matching Entra ID account automatically. Cornerstone holds the talent record and its OU structure; Joinly resolves the right person, then acts on the right account.
Joiner. A new user appears in Cornerstone with their Organizational Units set. Joinly reads the record through the Edge API, determines the role from Division, Position and Cost Center, and creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the start date and bound to the stable userId rather than a username that may change.
Mover. When someone changes Position, Division or Location in Cornerstone, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new OU placement is revoked, so permissions stay aligned with the actual role.
Leaver. When a user’s status moves to inactive or terminated in Cornerstone — or their end date passes — Joinly disables the Entra ID account automatically. No orphaned accounts are left active, and the matching is done on the internal Cornerstone ID, so a recycled username never disables the wrong person.
Example: A university hires a research administrator in Cornerstone, placed in the Division ‘Faculty of Science’ and Position ‘Grant Coordinator’, with a start date next Monday. Joinly reads the record, waits until the start date, creates the Entra ID account, assigns an Office E3 licence and adds the coordinator to the SCI-Research group. When that person later transfers to the Position ‘Department Manager’, Joinly swaps the groups the same day — matching on the unchanged Cornerstone userId, not the email address that the move also rewrote.
What manual user management costs
Without automation, every account starts as a Cornerstone export or a line in a spreadsheet that IT works through by hand. The native Entra provisioning app for Cornerstone has been deprecated and Cornerstone retired its Entra SCIM path, so there is no supported out-of-the-box bridge left — what remains is the SFTP Data Feed, a third-party connector or manual effort, and none of those decide access for you.
Onboarding delays. New joiners wait for accounts, licences and group access while a ticket sits in a queue, losing productive days in their first week.
Permissions that don’t keep up (privilege creep). When movers change Position or Division, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — and a username-based match can miss the right account entirely when an ID was recycled.
Joinly vs. the native Cornerstone provisioning options
The native Entra provisioning app for Cornerstone is deprecated and Cornerstone’s own Entra SCIM connector is gone, so the realistic alternatives are the SFTP Data Feed or a third-party connector. Here’s how that compares with Joinly for a Cornerstone-driven setup.
Joinly | SFTP Data Feed / connector / manual | |
|---|---|---|
Source | Reads the Cornerstone Edge API directly | Flat-file export or generic connector |
OU-to-group mapping | Built in, rule-based on Division / Position / Cost Center | Manual mapping; no role-to-group out of the box |
Identifier handling | Maps userId, username and SSO subject explicitly | Often keys on username — drifts when it changes |
Source-of-truth control | Pick the authoritative feed per attribute | Cornerstone OU data can overwrite better data |
Native Entra provisioning | Not needed — deprecated by Microsoft and Cornerstone | No supported native path remains |
Licence assignment | Driven by role / OU attributes | Manual or group-based only |
Audit trail | Per-action logging tied to the HR source | Limited |
Watch-outs when connecting Cornerstone OnDemand to Microsoft Entra ID
A few Cornerstone-specific details decide whether this connection stays reliable at scale.
Three identifiers that don’t auto-map. Cornerstone’s internal userId, the login username and the SSO subject are three separate things, and none derives from the others. Match on the wrong one and you update or disable the wrong account. Joinly keys on the stable userId and maintains the cross-system mapping, so a renamed username never breaks the link.
Cornerstone may not be your source of truth. Cornerstone is talent/learning-first, and its OU data is itself usually fed from an upstream HRIS. Joinly lets you set which feed is authoritative per attribute, so weaker Cornerstone OU values don’t silently overwrite better data from a core HR system.
Mapping Organizational Units to Entra groups. Division, Position, Location, Cost Center and Grade don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from those OUs to the correct groups and licences, so role drives access rather than manual assignment.
Reporting API lag and rate limits. The Reporting API reads the real-time data warehouse with a roughly 15-minute refresh, and high-volume reads are rate-limited. Joinly schedules reads sensibly and reconciles against the transactional API so a change isn’t missed or double-applied.
UPN format with duplicate names. When two users share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, location code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Cornerstone change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a university with around 9,000 staff and a large pool of seasonal teaching and research contracts, running Cornerstone OnDemand for learning and talent while its identity provisioning never quite keeps up. The old native Cornerstone-to-Entra app is gone, so accounts are created from a spreadsheet export — and because Cornerstone usernames get recycled and rewritten on transfers, the wrong account occasionally gets disabled when someone simply changes faculty.
Connect Cornerstone OnDemand to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each change in Cornerstone at the source, matches on the stable internal userId, and acts on it automatically: new hires have their account, Office licence and group access ready on their start date, transfers between Divisions swap the right groups the same day, and leavers are disabled on their end date with a 30-day soft-delete grace window.
“Recycled usernames used to be the thing that broke every sync — we once disabled an active professor by accident. Now Joinly keys on the Cornerstone ID, an account is simply ready on the start date, and we can show the auditor exactly which change created every bit of access.” — Head of IT, university
The outcome this setup is designed for: onboarding drops from days to zero touch, mismatched-identifier errors stop entirely, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone Cornerstone to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Cornerstone OnDemand to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the Cornerstone integration in the Joinly marketplace
Open the Joinly marketplace and search for the Cornerstone OnDemand integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Cornerstone OnDemand integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Cornerstone connection details: your portal (corp) URL, and the OAuth 2.0 Edge API credentials (client ID and secret) with the right scopes. Make sure the Cornerstone API and Reporting API are enabled under Admin > Tools > Edge > Integrations > Manage APIs. We only ask for the information needed to establish a successful connection with Cornerstone. All data is encrypted and stored securely.

Enter your Cornerstone portal URL and OAuth Edge API credentials in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Cornerstone fields.
Frequently asked questions
How do I map the manager? Reference the manager’s Cornerstone user identifier in the mapping and Joinly resolves the link to the right manager automatically.
Which identifier should I match on? Use the internal Cornerstone userId as the stable key, not the username, so renames and recycled logins never break the match.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map Cornerstone OU fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Cornerstone should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Cornerstone flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the end date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Cornerstone OnDemand to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Cornerstone OnDemand to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Cornerstone reach Entra ID quickly without waiting for a nightly batch. Joinly accounts for the Reporting API’s roughly 15-minute data-warehouse refresh so nothing is missed.
Which Cornerstone identifier does Joinly match on?
The stable internal userId. Cornerstone’s userId, username and SSO subject are three separate identifiers that don’t map to each other automatically, so Joinly keys on the userId and maintains the cross-system mapping — a renamed or recycled username never disables the wrong account.
What if Cornerstone isn’t our HRIS source of truth?
That’s common — Cornerstone is talent/learning-first and its OU data is often fed from an upstream HRIS. Joinly lets you set which feed is authoritative per attribute, so Cornerstone values only drive the attributes you trust them for.
Which attributes sync from Cornerstone to Entra ID?
Name, email / UPN, division, position, manager, location, cost center, grade, and start and end date. Custom Cornerstone fields can be mapped via Liquid templates.
Do I still need the native Entra provisioning app for Cornerstone?
No — and you couldn’t anyway. Microsoft deprecated the gallery provisioning app for Cornerstone and Cornerstone retired its Entra SCIM path. Joinly takes over the provisioning, OU-to-group mapping and identifier handling, and maintains it as your Cornerstone data changes.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Cornerstone OnDemand to Active Directory guide.


