Connect Kenjo to Microsoft Entra ID

Connect Kenjo to Microsoft Entra ID

Connect Kenjo to Microsoft Entra ID

When someone joins, moves or leaves in Kenjo, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Kenjo to Microsoft Entra ID, Joinly reads each HR change at the source — through the Kenjo API — and applies it automatically to the right account. Kenjo stays your source of truth; Joinly is the engine that keeps every action accurate and traceable.

Key takeaways

  • Kenjo stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically through the Kenjo API.

  • Joinly maps Kenjo’s own structures — office, department, team and area — to the right Entra ID groups and licences, which a plain API import can’t do on its own.

  • For deskless and shift-based staff who have no existing email, Joinly generates a unique, predictable UPN from your naming rules rather than depending on an address that isn’t there.

  • Kenjo has no native Entra provisioning app, so without Joinly the role-to-group and licence logic falls to a custom script or manual work; Joinly builds and maintains it for you.

  • Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.

Kenjo

Joiner

Mover

Leaver

Microsoft Entra ID (formerly Azure AD)

Quick facts

Source system

Kenjo (Kenjo HR)

Target system

Microsoft Entra ID (formerly Azure AD)

Connection method

Kenjo API → Entra ID

Supported events

Joiner, mover, leaver

Synced attributes

Name, email / UPN, department, team, office, area, job title, manager, start and end date

Authentication

Kenjo API key (Connect plan), scoped to the org and employee endpoints, over outbound HTTPS

Real-time or batch

Frequent sync, multiple times per day

Compliance

ISO 27001, NIS2-ready, GDPR (EU data centre)

How does Joinly sync Kenjo to Microsoft Entra ID?

Joinly reads each HR change in Kenjo through the API and applies it to the matching Entra ID account automatically. Kenjo holds the authoritative employee record, so it is the starting point for each identity action.

  1. Joiner. HR completes the hire in Kenjo. Joinly reads the new employee record and determines the role from attributes like office, department, team and area. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — generating a unique UPN even when the new starter has no existing email address.

  2. Mover. When someone changes department, team, office or area in Kenjo, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual job.

  3. Leaver. When Kenjo records that someone has left, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after a leaver, and no licence quietly keeps costing money.

Example: A hospitality group hires a front-desk supervisor in Kenjo, assigned to its Barcelona office and its Reception team. Joinly reads the record, creates the Entra ID account, assigns a Business Basic licence and adds the supervisor to the ES-Reception group. Because the new starter has no prior email, Joinly builds the UPN from a name rule with a collision fallback, so the login is unique from day one. When that supervisor later moves to the Events team, Joinly swaps the groups the same day.

What manual user management costs

Without automation, every account starts as a Kenjo notification or a line in a spreadsheet that IT works through by hand. Kenjo has no native Entra provisioning app, so even a scripted API import moves attributes but leaves the part that actually decides access — which groups, which licence, which UPN — to people.

  • Onboarding delays. New joiners wait for accounts, licences and group access while a request sits in a queue, losing productive time in their first shift or first week.

  • Permissions that don’t keep up (privilege creep). When movers change team, office or area, old access often stays attached, so people accumulate rights they no longer need.

  • Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — a real problem in high-turnover, shift-based teams.

Joinly vs. a custom Kenjo API import

Kenjo has no dedicated Entra provisioning app, so the alternative is a custom API-driven import (or Microsoft’s API-driven inbound provisioning). It can move attributes, but it stops short of the part that actually decides access. Here’s how the two compare for a Kenjo-driven setup.


Joinly

Custom Kenjo API / API-driven inbound provisioning

Source

Reads the Kenjo API directly

Reads the Kenjo API via custom code

Role-to-group mapping

Built in, rule-based on office / department / team / area

You build and maintain the logic yourself

UPN for staff with no email

Generated from name rules with a uniqueness fallback

Manual or scripted per case

Licence assignment

Driven by role / attributes

Manual or group-based only

On-premise AD

Yes, own agent plus the native Microsoft agent

Not covered without extra tooling

Maintenance

Managed and updated as Kenjo changes

Your team owns the script long-term

Audit trail

Per-action logging tied to the HR source

Whatever you build and log yourself

Watch-outs when connecting Kenjo to Microsoft Entra ID

A few Kenjo-specific details decide whether this connection stays reliable at scale.

  • Mapping Kenjo structures to Entra groups. Office, department, team and area don’t translate one-to-one to Entra ID groups, and in an SME the data is often lighter than in enterprise HCM. Joinly builds explicit mapping rules from those structures to the correct groups and licences, so role drives access rather than manual assignment.

  • Staff without a company email. Kenjo is built for deskless and shift-based teams, so many new starters have no existing email to copy a UPN from. Joinly generates a unique UPN and display name from your naming rules, with a controlled tiebreaker for duplicate names.

  • API key scope on the Connect plan. The Kenjo API is enabled per account and each key is scoped. The key must be granted the office, department, team, area and employee endpoints. Joinly tells you exactly which scopes to enable, so the sync has the data it needs without over-granting access.

  • High turnover and rehires. Shift-based workforces churn, and the same person may return. Joinly matches returning people to their existing account instead of creating duplicates, and disables leavers promptly so licences aren’t wasted.

Joinly handles each of these by default with custom mapping and transformation.

Always audit-ready

Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Kenjo change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.

Example case

Picture a hospitality group with around 1,800 employees across a dozen hotels and restaurants, running Kenjo for its shift-based teams while identity is still handled by hand. Most front-of-house and kitchen staff have no company email when they start, so IT builds each Entra ID account manually from the Kenjo record — inventing a login, picking the licence, adding groups. With seasonal peaks and high turnover the queue never empties, and a new waiter or receptionist often waits until their second or third shift before they can clock in on the systems they need.

Connect Kenjo to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each change in Kenjo at the source and acts on it automatically: new hires have their account, licence and group access ready in time for their first shift, a move from Reception to Events swaps the right groups the same day, returning seasonal staff are matched back to their old account instead of getting a duplicate, and leavers are disabled promptly so no licence keeps billing.

“Half our people start without an email, so every account used to be a manual build. Now a login is simply ready before the shift starts, a team change just swaps the groups, and we can show exactly which Kenjo change created every bit of access.” — Head of IT, hospitality group

The outcome this setup is designed for: onboarding drops from days to zero touch for shift staff, privilege creep from old teams is eliminated, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.

More than a connector

A standalone Kenjo to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.

Schedule a demo

Installation manual

Installation manual

Connect Kenjo to Microsoft Entra ID

Connect Kenjo to Microsoft Entra ID

Installation guide

Follow these steps to connect Kenjo to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.

1. Create your account

Go to platform.joinly.app and create your account.

Note: charges may apply for using the platform after the trial period ends.


Joinly account creation screen at platform.joinly.app


Sign up at platform.joinly.app to get started.

2. Connect your Microsoft account

Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.


Joinly identity provider setup screen for connecting a Microsoft Entra tenant


Connect your Microsoft tenant and pick your scopes.

3. Import your existing accounts from Entra ID

Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.

4. Enable the Kenjo API and generate a key

In Kenjo, go to Settings → Integrations and toggle API on (available on the Connect plan). Then generate an API key under API Keys and grant it access to the company, office, department, team, area and employee endpoints. Copy the key immediately — Kenjo only shows it once.

5. Find the Kenjo integration in the Joinly marketplace

Open the Joinly marketplace and search for the Kenjo integration.

Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.


Joinly marketplace showing available HR integrations


Search the marketplace for the Kenjo integration.

6. Follow the installation wizard

You may be redirected to integrations.joinly.app. Create an account there and enter your Kenjo connection details: your Kenjo API key and the endpoints you enabled. We only ask for the information needed to establish a successful connection with Kenjo. All data is encrypted and stored securely.


Joinly installation wizard for entering Kenjo connection details


Enter your Kenjo API key and connection details in the wizard.

7. Configure your field mapping

Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Kenjo fields.

Frequently asked questions

  • How do I map the manager? Reference the manager on the Kenjo employee record in the mapping and Joinly resolves the link to the right manager automatically.

  • How do I map office, department, team and area? Use them as inputs to your group and licence rules, so Kenjo’s structure drives Entra membership.

  • How do I prevent duplicate usernames? Use the generateUniqueUsername helper, which falls back to the next pattern when the first one is already taken:
    {{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}


Joinly field mapping screen for Kenjo attributes using Liquid templates


Map Kenjo fields to Entra ID attributes with Liquid templates.

8. Configure the scheduled import

At platform.joinly.app/settings/import-configs, configure how often the import from Kenjo should run.

9. Configure your workflows

Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Kenjo flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the leave date (for example 30 days) to retire accounts safely.


Joinly workflow editor creating an employee onboarding workflow


Create a trigger-based onboarding workflow.


Adding the create or update employee in Entra action to a workflow


Add the create/update action, then set your matching strategy and field mapping.


Adding the Entra soft delete action to remove accounts on employee leave


Add the Entra soft delete action to retire accounts safely.

## AD on-premise support

Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Kenjo to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.

Frequently asked questions

Does the Kenjo to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Kenjo reach Entra ID quickly without waiting for a nightly batch.

How does Joinly handle new starters who have no company email?
Joinly generates a unique UPN and display name from your naming rules, with a controlled fallback for duplicate names, so shift and deskless staff get a valid login even though there is no existing address to copy.

Do I need a special Kenjo plan or API access?
Yes. The Kenjo API is enabled under Settings > Integrations and is available on Kenjo’s Connect plan. You generate a scoped API key and grant it the office, department, team, area and employee endpoints that Joinly needs.

Which attributes sync from Kenjo to Entra ID?
Name, email / UPN, department, team, office, area, job title, manager, and start and end date. Additional Kenjo fields can be mapped via Liquid templates.

Does Kenjo have its own Entra provisioning app?
No. Kenjo has no dedicated Entra ID gallery or SCIM provisioning app, so without Joinly you would build and maintain a custom API import yourself. Joinly provides the role-to-group mapping, UPN generation and offboarding logic out of the box and keeps it current as your Kenjo data changes.

Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Kenjo to Active Directory guide.

Request installation support