Connect Hailey HR to Microsoft Entra ID

Connect Hailey HR to Microsoft Entra ID

Connect Hailey HR to Microsoft Entra ID

When someone joins, moves or leaves in Hailey HR, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Hailey HR to Microsoft Entra ID, Joinly reads each HR change at the source — through the Hailey HR API — and applies it automatically to the right account, including the role-to-group mapping and licence assignment Hailey’s own integration leaves to you. Hailey stays your source of truth; Joinly is the engine that keeps every action accurate and traceable.

Key takeaways

  • Hailey HR Core stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically.

  • Joinly maps Hailey’s org data — department, legal entity, location and title — to the right Entra ID groups and licences, something Hailey’s own Entra integration does not do.

  • Joinly reads the Hailey HR API directly and can act on data-change webhooks, so a change in Hailey reaches Entra ID quickly instead of waiting on an hourly one-way sync.

  • Joinly builds the UPN and display name from your own rules with a uniqueness fallback, so duplicate names never collide.

  • Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.

Hailey HR

Joiner

Mover

Leaver

Microsoft Entra ID (formerly Azure AD)

Quick facts

Source system

Hailey HR (HR Core)

Target system

Microsoft Entra ID (formerly Azure AD)

Connection method

Hailey HR API → Entra ID

Supported events

Joiner, mover, leaver (incl. rehire and department/location changes)

Synced attributes

Name, email / UPN, department, title, manager, legal entity, location, employment number, start and end date

Authentication

Hailey HR API key (access token requested from Hailey Support)

Real-time or batch

Frequent sync, multiple times per day

Compliance

ISO 27001, NIS2-ready, GDPR (EU data centre)

How does Joinly sync Hailey HR to Microsoft Entra ID?

Joinly reads each HR change in Hailey through the Hailey HR API and applies it to the matching Entra ID account automatically. Hailey HR Core holds the authoritative employment record, so it is the starting point for each identity action.

  1. Joiner. HR completes the hire in Hailey. Joinly reads the new employee and employment record and determines the role from attributes like department, location and title. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the employment start date.

  2. Mover. When someone changes department, location or title in Hailey, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual job.

  3. Leaver. On the end date recorded in Hailey, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and a soft-delete grace window lets you retire the account safely once the notice period has passed.

Example: A fast-growing SaaS company runs Hailey HR and hires a customer-success specialist with a start date next Monday. Joinly reads the employment record, waits until the start date, creates the Entra ID account, assigns an Office E3 licence and adds the specialist to the CS-Team and Amsterdam-Office groups. When that person later moves from Support into Product, Joinly swaps the groups and licences the same day — the kind of role-to-group logic Hailey’s built-in Entra sync leaves to a person.

What manual user management costs

Without automation, every account starts as a message in Slack or a line in a spreadsheet that IT works through by hand. Hailey’s native Entra integration can push a fixed set of fields across on an hourly sync, but it maps no roles to groups, assigns no licences and never touches an OU — so the part that actually decides access still falls to people.

  • Onboarding delays. New joiners wait for accounts, licences and group access while someone gets around to the request, losing productive days in their first week.

  • Permissions that don’t keep up (privilege creep). When movers change department or role, old access often stays attached, so people accumulate rights they no longer need.

  • Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — a real cost for a lean team where every seat counts.

Joinly vs. Hailey’s native Entra ID integration

Hailey’s built-in Microsoft Entra integration is a fine baseline for basic account creation, but it stops short of the part that actually decides access. Here’s how the two compare for a Hailey-driven setup.


Joinly

Hailey native Entra integration

Source

Reads the Hailey HR API directly

Reads Hailey directly (Hailey as master)

Role-to-group mapping

Built in, rule-based on department / location / title

Not available — fixed field sync only

Sync cadence

Frequent sync, multiple times per day; webhook-aware

Hourly one-directional sync

Licence assignment

Driven by role / attributes

Not available

On-premise AD

Yes, own agent plus the native Microsoft agent

Not supported — cloud Entra only

Audit trail

Per-action logging tied to the HR source

Limited

Watch-outs when connecting Hailey HR to Microsoft Entra ID

A few Hailey-specific details decide whether this connection stays reliable as you grow.

  • API key scope and access rights. Hailey’s API returns employee data according to the rights attached to the key, and the key itself is requested from Hailey Support. Joinly connects with a correctly scoped key and matches people to existing Entra accounts on import, so you get complete data without creating duplicates.

  • Mapping a flat org model to Entra groups. Hailey’s department, legal entity and location fields are flexible rather than a deep hierarchy, so they don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from those fields to the correct groups and licences, so role drives access rather than manual assignment.

  • Filling the gaps Hailey’s native sync leaves. The built-in Entra integration syncs a fixed field set on an hourly, one-way basis with no role-to-group, licence or OU logic. Joinly takes over that decision-making layer, so onboarding produces a fully provisioned account, not just a bare user object.

  • UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, a location code or a controlled tiebreaker — so every UPN is unique and predictable from day one.

  • Start dates and timing. Joinly reads the employment start date on the Hailey record and times account creation to it, so access is ready on the right day rather than the moment HR saved the hire.

Joinly handles each of these by default with custom mapping and transformation.

Always audit-ready

Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Hailey HR change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.

Example case

Picture a fast-growing SaaS startup with around 180 employees across two European offices, running Hailey HR as its HR core while its identity setup is held together by a shared spreadsheet and the odd Slack ping to IT. Hailey’s native Entra sync creates the bare account, but every new hire still needs someone to add the right groups, assign a licence and check the office and team are correct — and with hiring running hot, those manual steps are exactly where people slip through onboarding without the access they need.

Connect Hailey HR to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change in Hailey at the source and acts on it automatically: new hires have their account, Office licence and group access ready on their start date, a move from Support into Product swaps the right groups and licences the same day, and leavers are disabled on their end date with a soft-delete grace window.

“Hailey’s own Entra sync gave us an empty account and nothing else — we were still adding groups and licences by hand for every hire. Now the account is simply ready with the right access on day one, and we can show exactly which Hailey change created it.” — Head of IT, SaaS scale-up

The outcome this setup is designed for: onboarding drops from days to zero touch, licence spend stops leaking on forgotten accounts, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.

More than a connector

A standalone Hailey HR to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.

Schedule a demo

Installation manual

Installation manual

Connect Hailey HR to Microsoft Entra ID

Connect Hailey HR to Microsoft Entra ID

Installation guide

Follow these steps to connect Hailey HR to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.

1. Create your account

Go to platform.joinly.app and create your account.

Note: charges may apply for using the platform after the trial period ends.


Joinly account creation screen at platform.joinly.app


Sign up at platform.joinly.app to get started.

2. Connect your Microsoft account

Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.


Joinly identity provider setup screen for connecting a Microsoft Entra tenant


Connect your Microsoft tenant and pick your scopes.

3. Import your existing accounts from Entra ID

Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.

4. Find the Hailey HR integration in the Joinly marketplace

Open the Joinly marketplace and search for the Hailey HR integration.

Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.


Joinly marketplace showing available HR integrations


Search the marketplace for the Hailey HR integration.

5. Follow the installation wizard

You may be redirected to integrations.joinly.app. Create an account there and enter your Hailey HR connection details: your Hailey HR API key (the access token you request from Hailey Support). We only ask for the information needed to establish a successful connection with Hailey HR. All data is encrypted and stored securely.


Joinly installation wizard for entering Hailey HR connection details


Enter your Hailey HR API key in the wizard.

6. Configure your field mapping

Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Hailey fields.

Frequently asked questions

  • How do I map the manager? Reference the manager on the Hailey employment record in the mapping and Joinly resolves the link to the right manager automatically.

  • How do I map departments to groups? Build a rule from the Hailey department, legal entity and location fields to the target Entra groups and licences.

  • How do I prevent duplicate usernames? Use the generateUniqueUsername helper, which falls back to the next pattern when the first one is already taken:
    {{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}


Joinly field mapping screen for Hailey HR attributes using Liquid templates


Map Hailey HR fields to Entra ID attributes with Liquid templates.

7. Configure the scheduled import

At platform.joinly.app/settings/import-configs, configure how often the import from Hailey HR should run.

8. Configure your workflows

Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Hailey flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the end date (for example 30 days) to retire accounts safely.


Joinly workflow editor creating an employee onboarding workflow


Create a trigger-based onboarding workflow.


Adding the create or update employee in Entra action to a workflow


Add the create/update action, then set your matching strategy and field mapping.


Adding the Entra soft delete action to remove accounts on employee leave


Add the Entra soft delete action to retire accounts safely.

## AD on-premise support

Need to provision to an on-premise Active Directory as well? Hailey’s own integration is cloud-Entra only, but Joinly can. See our dedicated guide on connecting Hailey HR to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.

Frequently asked questions

Does the Hailey HR to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day and can act on Hailey’s data-change webhooks, so changes in Hailey reach Entra ID quickly — faster than Hailey’s own hourly, one-directional native sync.

How is this different from Hailey’s built-in Entra integration?
Hailey’s native integration creates an account and syncs a fixed set of fields on an hourly one-way basis, but it does no role-to-group mapping, no licence assignment and no OU placement, and it doesn’t support on-premise AD. Joinly adds exactly that decision-making layer, so onboarding produces a fully provisioned account.

How does Joinly authenticate to Hailey HR?
With a Hailey HR API key — the access token you request from Hailey Support. The rights on the key determine which employee data is returned, so Joinly connects with a correctly scoped key.

Which attributes sync from Hailey HR to Entra ID?
Name, email / UPN, department, title, manager, legal entity, location, employment number, and start and end date. Additional fields can be mapped via Liquid templates.

Do I still need Hailey’s native Entra integration?
No. Joinly takes over the provisioning, role-to-group mapping and licence assignment that the native integration does not do, and maintains it as your Hailey data changes.

Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well — something Hailey’s own integration cannot do. See the Hailey HR to Active Directory guide.

Request installation support