When someone joins, moves or leaves in Infor HCM, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Infor HCM to Microsoft Entra ID, Joinly reads each HR change in Global HR at the source — through the Infor ION API Gateway and the BOD events ION publishes — and applies it automatically to the right account. Infor Global HR stays your source of truth; Joinly is the engine that keeps every action accurate and traceable.
Key takeaways
Global HR stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically.
Joinly speaks Infor ION directly — it authenticates to the IONAPI gateway and consumes the person and work-assignment BODs, so you don’t build and maintain a custom ION integration yourself.
Joinly maps Global HR building blocks — organization unit, position, job and work assignment — to the right Entra ID groups and licences, which a raw ION BOD feed leaves entirely to you.
Joinly reads effective-dated work assignments, so future-dated hires are provisioned exactly on their start date and not the moment HR enters them.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | Infor HCM (Global HR) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Infor ION API Gateway (IONAPI) + BOD events → Entra ID |
Supported events | Joiner, mover, leaver (incl. rehire, transfer, multiple work assignments) |
Synced attributes | Name, email / UPN, organization unit, position, job title, manager, location, work assignment, start and end date |
Authentication | OAuth 2.0 client credentials via .ionapi credentials file |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Infor HCM to Microsoft Entra ID?
Joinly authenticates to the Infor ION API Gateway and reads each HR change Global HR publishes as a BOD, then applies it to the matching Entra ID account automatically. Global HR holds the authoritative people record and work assignment, so it is the starting point for each identity action.
Joiner. HR completes the hire in Global HR. Joinly reads the new person record and its work assignment over IONAPI and determines the role from attributes like organization unit, position and job. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the effective start date of the work assignment.
Mover. When someone’s work assignment changes — a new position, organization unit or location — Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new assignment is revoked, so permissions stay aligned with the actual job.
Leaver. On the termination date recorded in Global HR, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and multiple work assignments are taken into account so access is only removed when the last active assignment ends.
Example: An industrial distribution group hires a regional fulfilment planner in Global HR with a start date next Monday, in a position under its Benelux organization unit. Joinly reads the effective-dated work assignment over IONAPI, waits until the start date, creates the Entra ID account, assigns an Office E3 licence and adds the planner to the BNL-Operations group. When that planner later picks up a second work assignment in a procurement position, Joinly keeps the primary assignment as the driver of the UPN and adds the extra group without breaking sign-in.
What manual user management costs
Without automation, every account starts as an Infor HCM ticket or a line in a spreadsheet that IT works through by hand. A custom ION/IONAPI integration with BOD document flows can move attributes across, but it is built and maintained by your integration team, has no concept of role-to-group mapping, and inherits ION’s asynchronous, effective-dated quirks — so the part that actually decides access still falls to people.
Onboarding delays. New joiners wait for accounts, licences and group access while a ticket sits in a queue, losing productive days in their first week.
Permissions that don’t keep up (privilege creep). When movers change position or organization unit, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — and with multiple work assignments it is easy to disable an account while another assignment is still active.
Joinly vs. a custom ION integration
There is no first-party Infor inbound provisioning app for Entra ID — the realistic alternative is a custom ION/IONAPI integration your team builds with BOD document flows. (Microsoft’s Entra connector for Infor CloudSuite is SCIM outbound for app access, not an HR-driven feed.) Here’s how the two compare for a Global HR-driven setup.
Joinly | Custom ION / IONAPI integration | |
|---|---|---|
Source | Reads Global HR via IONAPI and BODs out of the box | You build and maintain the ION document flows yourself |
Role-to-group mapping | Built in, rule-based on organization unit and position | No concept of it; coded by hand per group |
Effective-dated / future hires | Times account creation to the effective start date | Must be handled in your own integration logic |
Multiple work assignments | Resolves the primary assignment for the UPN | Ambiguous; whichever BOD you process can win |
Asynchronous BOD handling | Built in; waits for the Acknowledge before acting | You manage the pending state and retries |
Licence assignment | Driven by role / attributes | Not provided; out of scope for a raw BOD feed |
Audit trail | Per-action logging tied to the HR source | Whatever you log yourself |
Watch-outs when connecting Infor HCM to Microsoft Entra ID
A few Infor-specific details decide whether this connection stays reliable at scale.
Everything routes through Infor ION. Global HR has no point-to-point HR API; identity data is only reachable through the ION API Gateway and the document flows that publish person and work-assignment BODs. Joinly authenticates to IONAPI with the .ionapi credentials and subscribes to the right BODs, so you don’t stand up and babysit a bespoke ION integration.
Asynchronous BOD messaging. ION is event-driven and asynchronous: a request moves through a pending state until an Acknowledge BOD comes back, so a record isn’t usable the instant it’s sent. Joinly handles that handshake and retries, so provisioning waits for confirmation instead of acting on a half-applied change.
Effective-dated work assignments. Global HR stores a hire or transfer as an effective-dated work assignment well before it is active, and provisioning too early or too late both cause problems. Joinly reads the effective date and times account creation to it, so access is ready on the right day and not before.
Work assignment vs position vs organization unit. These building blocks don’t translate one-to-one to Entra ID groups, and a person can hold more than one work assignment. Joinly builds explicit mapping rules from position and organization unit to the correct groups and licences, and picks the primary assignment to drive the UPN.
UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, organization-unit code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Infor HCM change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture an industrial distribution group with around 5,000 employees across several operating companies, running Infor CloudSuite HCM as its HR core while its identity provisioning never quite keeps up. A custom ION integration handles the simple cases, yet seasonal warehouse contracts, transfers between operating companies and a steady stream of second work assignments keep breaking it — planners with a procurement assignment alongside their main role end up with the wrong assignment driving Entra ID, and future-dated hires are provisioned the moment HR saves the record rather than on their actual start date.
Connect Infor HCM to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change in Global HR over IONAPI and acts on it automatically: new hires have their account, Office licence and group access ready on their effective start date, transfers between operating companies swap the right groups the same day, second work assignments keep a single, stable UPN, and leavers are disabled on their termination date with a 30-day soft-delete grace window.
“Multiple work assignments and the ION handshake used to break every sync we built. Now an account is simply ready on the start date, a second assignment just adds access, and we can show the auditor exactly which Infor change created every bit of access.” — Head of IT, industrial distribution group
The outcome this setup is designed for: onboarding drops from days to zero touch, work-assignment errors stop entirely, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone Infor HCM to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Infor HCM to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the Infor HCM integration in the Joinly marketplace
Open the Joinly marketplace and search for the Infor HCM integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Infor HCM integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Infor connection details: your ION API Gateway base URL and the OAuth 2.0 credentials from your authorised app’s .ionapi file (client ID, client secret and token endpoint). We only ask for the information needed to establish a successful connection with Infor ION. All data is encrypted and stored securely.

Enter your ION API Gateway URL and .ionapi OAuth credentials in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Global HR fields.
Frequently asked questions
How do I map the manager? Reference the manager’s resource identifier from the work assignment and Joinly resolves the link to the right manager automatically.
How do I handle multiple work assignments? Pick the primary assignment as the driver for the UPN; Joinly exposes the active work assignments so you can choose the primary one.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map Global HR fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Infor HCM should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Global HR flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the termination date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Infor HCM to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Infor HCM to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Global HR reach Entra ID quickly without waiting for a nightly batch. ION’s asynchronous BOD handshake is handled for you.
How does Joinly handle multiple work assignments?
Joinly reads all active work assignments for a person and applies your rules to pick the primary assignment as the driver for the UPN, so a second assignment adds access without creating a duplicate account or breaking sign-in.
How are future-dated hires handled?
Joinly reads the effective date on the Global HR work assignment and times account creation to it, so access is ready on the start date rather than the moment HR saved the record.
Which attributes sync from Infor HCM to Entra ID?
Name, email / UPN, organization unit, position, job title, manager, location, work assignment, and start and end date. Additional Global HR fields can be mapped via Liquid templates.
Do I still need a custom ION integration?
No. Joinly authenticates to the IONAPI gateway and consumes the person and work-assignment BODs for you, taking over the provisioning, role-to-group mapping and asynchronous handling that a bespoke ION integration leaves to your team.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Infor HCM to Active Directory guide.


