Connect Justworks to Microsoft Entra ID

Connect Justworks to Microsoft Entra ID

Connect Justworks to Microsoft Entra ID

When someone joins, moves or leaves in Justworks, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Justworks to Microsoft Entra ID, Joinly reads each member change in the Justworks directory through a unified HR API connector and applies it automatically to the right account. Justworks stays your source of truth; Joinly is the engine that keeps every action accurate and traceable — including the difference between employees and contractors.

Key takeaways

  • Justworks stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically.

  • Joinly maps Justworks member attributes — title, department, manager and office — to the right Entra ID groups and licences, which no native Justworks-to-Entra path does on its own.

  • Because Justworks has no public provisioning API or SCIM endpoint, Joinly reads the directory through a unified HR API connector and treats Justworks as a read source of truth.

  • Contractors and employees are handled with separate rules, so a contractor doesn’t automatically receive a full employee account and licence footprint.

  • Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001, running in an EU data centre on the Joinly side.

Justworks

Joiner

Mover

Leaver

Microsoft Entra ID (formerly Azure AD)

Quick facts

Source system

Justworks (member directory)

Target system

Microsoft Entra ID (formerly Azure AD)

Connection method

Justworks directory via unified HR API connector → Entra ID

Supported events

Joiner, mover, leaver (incl. rehire and contractor-vs-employee handling)

Synced attributes

Name, email / UPN, department, title, manager, office, member type, start and end date

Authentication

Authorised connector credentials; no deprecated basic auth or exposed domain controller

Real-time or batch

Frequent sync, multiple times per day

Compliance

ISO 27001, NIS2-ready, GDPR (EU data centre)

How does Joinly sync Justworks to Microsoft Entra ID?

Joinly reads each member change in the Justworks directory through a unified HR API connector and applies it to the matching Entra ID account automatically. Justworks holds the authoritative member record — title, department, manager, office and member type — so it is the starting point for each identity action.

  1. Joiner. An admin adds the new member in Justworks with a title, department and manager. Joinly reads the new member record and determines the role from title, department and office. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups. For contractors, Joinly applies a separate rule so they get a scoped account rather than a full employee footprint.

  2. Mover. When someone changes title, department or manager in Justworks, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new role is revoked, so permissions stay aligned with the actual job rather than accumulating over time.

  3. Leaver. When a member is offboarded in Justworks and their end date passes, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and unused licences are freed rather than quietly billed month after month.

Example: A creative agency adds a new motion designer in Justworks with the title Motion Designer, the Creative department and an office in New York. Joinly reads the member record, creates the Entra ID account, assigns a Microsoft 365 Business Premium licence and adds the designer to the Creative and NYC-Office groups. When the agency later brings on a freelance editor as a contractor, Joinly applies the contractor rule: a scoped account with project-tool access only, no full licence, and automatic deactivation when the contract ends.

What manual user management costs

Without automation, every account starts as a note from HR or a line in a spreadsheet that IT works through by hand. Because Justworks exposes no native Entra provisioning app, the usual fallback is a unified-API connector or a CSV export that copies attributes across — but neither decides who belongs in which group, and neither knows a contractor from an employee, so the part that actually determines access still falls to people.

  • Onboarding delays. New joiners wait for accounts, licences and group access while a request sits in a queue, losing productive days in their first week.

  • Permissions that don’t keep up (privilege creep). When members change title or department, old access often stays attached, so people accumulate rights they no longer need.

  • Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused Microsoft licences keep costing money — an avoidable expense for a small team watching its budget.

Joinly vs. a generic HR-API connector

There is no Microsoft-published Entra inbound provisioning app for Justworks, so the default is a generic unified-API connector or a manual CSV import. Those are a fine way to copy attributes, but they stop short of the part that actually decides access. Here’s how the two compare for a Justworks-driven setup.


Joinly

Generic HR-API connector / CSV import

Source

Reads the Justworks directory via a unified HR API connector

Reads Justworks attributes and passes them through

Role-to-group mapping

Built in, rule-based on title, department and office

Attribute copy only; no role-to-group out of the box

Contractor vs employee

Separate rules per member type

Treated the same unless you script it yourself

Licence assignment

Driven by role / attributes

Manual or group-based only

On-premise AD

Yes, own agent plus the native Microsoft agent

Not covered; cloud attributes only

Audit trail

Per-action logging tied to the HR source

Limited

Watch-outs when connecting Justworks to Microsoft Entra ID

A few Justworks-specific details decide whether this connection stays reliable as your team grows.

  • No public provisioning API or SCIM. Justworks doesn’t publish an open lifecycle API or a SCIM endpoint, so Joinly reads the directory through a unified HR API connector and treats Justworks as a read source of truth. Provisioning decisions happen in Joinly, which keeps the connection stable even as Justworks changes.

  • Contractors alongside employees. Justworks lists contractors and employees together as members. A naive rule would give a contractor the same account and licences as staff. Joinly keys off the member type so contractors get a scoped account and employees get the full footprint.

  • PEO co-employment model. As a PEO, Justworks is the co-employer of record for payroll and benefits, but you keep control of hiring, titles and comp — the very fields that should drive access. Joinly reads exactly those fields, so provisioning follows your decisions rather than the payroll relationship.

  • Flat department structure. Justworks puts a member in one department at a time with no department hierarchy. Joinly builds explicit mapping rules from title, department and office to the correct Entra groups and licences, so a flat source still drives a rich group model.

  • UPN format with duplicate names. When two members share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, office code or controlled tiebreaker — so every UPN is unique and predictable from day one.

Joinly handles each of these by default with custom mapping and transformation.

Always audit-ready

Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Justworks change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.

Example case

Picture a creative agency of around 120 people across two offices, running Justworks for payroll and HR while its Microsoft 365 accounts are set up by hand. New designers, producers and freelancers arrive in bursts around big campaigns, and every one of them starts as a message to the office manager who creates the account, guesses the right groups and picks a licence. Freelancers routinely end up with full staff licences that nobody remembers to cancel, and when a contract ends the account often lingers for weeks.

Connect Justworks to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each member change in Justworks and acts on it automatically: new employees have their account, Microsoft 365 licence and group access ready on day one, contractors get a scoped account with no full licence, role changes swap the right groups the same day, and leavers are disabled when their end date passes with a soft-delete grace window.

“We used to give every freelancer a full licence and forget to turn it off. Now a designer is ready on day one, a freelancer gets exactly what the project needs, and nothing lingers after a contract ends.” — Head of IT, creative agency

The outcome this setup is designed for: onboarding drops from days to zero touch, contractor accounts stop leaking licence spend, and the team can show exactly which Justworks change created every bit of access.

More than a connector

A standalone Justworks to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.

Schedule a demo

Installation manual

Installation manual

Connect Justworks to Microsoft Entra ID

Connect Justworks to Microsoft Entra ID

Installation guide

Follow these steps to connect Justworks to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.

1. Create your account

Go to platform.joinly.app and create your account.

Note: charges may apply for using the platform after the trial period ends.


Joinly account creation screen at platform.joinly.app


Sign up at platform.joinly.app to get started.

2. Connect your Microsoft account

Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.


Joinly identity provider setup screen for connecting a Microsoft Entra tenant


Connect your Microsoft tenant and pick your scopes.

3. Import your existing accounts from Entra ID

Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.

4. Find the Justworks integration in the Joinly marketplace

Open the Joinly marketplace and search for the Justworks integration.

Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.


Joinly marketplace showing available HR integrations


Search the marketplace for the Justworks integration.

5. Follow the installation wizard

You may be redirected to integrations.joinly.app. Create an account there and authorise the Justworks connection. Because Justworks has no public provisioning API, Joinly reads the member directory through a unified HR API connector; you grant access once and Joinly keeps the read in sync. We only ask for the information needed to establish a successful connection with Justworks. All data is encrypted and stored securely.


Joinly installation wizard for entering Justworks connection details


Authorise the Justworks connection in the wizard.

6. Configure your field mapping

Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Justworks member fields.

Frequently asked questions

  • How do I map the manager? Reference the member’s manager in the mapping and Joinly resolves the link to the right manager automatically.

  • How do I handle contractors? Key your rules off the member type so contractors get a scoped account and employees get the full footprint.

  • How do I prevent duplicate usernames? Use the generateUniqueUsername helper, which falls back to the next pattern when the first one is already taken:
    {{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}


Joinly field mapping screen for Justworks attributes using Liquid templates


Map Justworks fields to Entra ID attributes with Liquid templates.

7. Configure the scheduled import

At platform.joinly.app/settings/import-configs, configure how often the import from Justworks should run.

8. Configure your workflows

Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Justworks flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the end date (for example 30 days) to retire accounts safely.


Joinly workflow editor creating an employee onboarding workflow


Create a trigger-based onboarding workflow.


Adding the create or update employee in Entra action to a workflow


Add the create/update action, then set your matching strategy and field mapping.


Adding the Entra soft delete action to remove accounts on employee leave


Add the Entra soft delete action to retire accounts safely.

## AD on-premise support

Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Justworks to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.

Frequently asked questions

Does the Justworks to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Justworks reach Entra ID quickly without waiting for a nightly batch.

Does Justworks have an API for provisioning?
Justworks doesn’t publish a public provisioning API or a SCIM endpoint, so Joinly reads the member directory through a unified HR API connector and treats Justworks as a read source of truth. All the provisioning logic — group mapping, licences, contractor handling — happens in Joinly.

How does Joinly tell contractors apart from employees?
Justworks lists both as members with a member type. Joinly keys its rules off that type, so a contractor gets a scoped account without a full licence while employees get the complete footprint.

Which attributes sync from Justworks to Entra ID?
Name, email / UPN, department, title, manager, office, member type, and start and end date. Additional fields can be mapped via Liquid templates.

Do I still need a separate HR-API connector or CSV import?
No. Joinly takes over the read from Justworks and adds the role-to-group mapping, licence assignment and contractor handling that a generic connector or CSV import leaves to you, and maintains it as your Justworks data changes.

Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Justworks to Active Directory guide.

Request installation support