When someone joins, moves or leaves in Namely, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Namely to Microsoft Entra ID, Joinly reads each HR change through the Namely REST API at the source and applies it automatically to the right account. Namely stays your source of truth; Joinly is the engine that keeps every action accurate and traceable — the piece Namely’s SSO-only Entra app leaves out.
Key takeaways
Namely stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically over the Namely REST API.
Namely’s own Entra/Azure AD gallery app is single sign-on only — it does not provision accounts — so Joinly fills the HR-driven joiner/mover/leaver gap.
Joinly maps Namely Groups, Group Types, Departments and Job Titles to the right Entra ID groups and licences, which SSO and generic SCIM setups can’t do on their own.
Joinly reads user_status and employee_type, so active, inactive and guest profiles drive the correct account state instead of a blunt on/off toggle.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | Namely (Namely HRIS) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Namely REST API → Entra ID |
Supported events | Joiner, mover, leaver (incl. rehire and status changes) |
Synced attributes | Name, email / UPN, department, job title, manager (reports to), group, employee type, start and end date |
Authentication | OAuth 2.0 authorization code, or Personal Access Token (Bearer) |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Namely to Microsoft Entra ID?
Joinly reads each HR change in Namely through the REST API and applies it to the matching Entra ID account automatically. Namely holds the authoritative employee record, so its Profiles endpoint is the starting point for every identity action.
Joiner. HR completes the hire in Namely. Joinly reads the new profile — job title, department, the Groups the person belongs to and their reports-to manager — and determines the role from those attributes. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups, ready on the recorded start date.
Mover. When someone’s job title, department or Group membership changes in Namely, Joinly updates their Entra ID group membership, permissions and licences to match. Access that no longer fits the new role is revoked, so permissions stay aligned with the actual job.
Leaver. When a profile’s user_status changes to an inactive status on the termination date in Namely, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and rehires are matched back to the existing account instead of creating a duplicate.
Example: A digital media company hires a video editor in Namely, in its Content department, with a start date next Monday. Joinly reads the profile, waits until the start date, creates the Entra ID account, assigns a Microsoft 365 E3 licence and adds the editor to the Content-Production group based on their Namely Group. When that editor later moves into the Brand team, Joinly swaps the group membership the same day, without anyone opening a ticket.
What manual user management costs
Without automation, every account starts as a Namely note or a line in a spreadsheet that IT works through by hand. Namely’s Entra gallery app only covers single sign-on, and generic SCIM or third-party connectors move a few attributes across but map roles to groups by hand — so the part that actually decides access still falls to people.
Onboarding delays. New joiners wait for accounts, licences and group access while a request sits in a queue, losing productive days in their first week.
Permissions that don’t keep up (privilege creep). When movers change job title, department or Group in Namely, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — and an SSO-only setup does nothing to deprovision the account behind the login.
Joinly vs. Namely’s native Entra options
Namely publishes an Entra/Azure AD gallery app for single sign-on, but there is no first-party inbound provisioning connector — so the alternative is Microsoft’s generic API-driven / SCIM inbound provisioning or a third-party SSO tool. Here’s how the two compare for a Namely-driven setup.
Joinly | Namely SSO app / generic SCIM | |
|---|---|---|
Source | Reads the Namely REST API directly | SSO only; provisioning needs a separate SCIM bridge |
Role-to-group mapping | Built in, rule-based on Groups, departments and job titles | Manual attribute mapping; no role-to-group out of the box |
Joiner / mover / leaver | Full HR-driven lifecycle from Namely | SSO does not create, move or disable accounts |
Status / employee type | Maps user_status and employee_type to account state | Blunt active/inactive toggle at best |
Licence assignment | Driven by role / attributes | Manual or group-based only |
On-premise AD | Yes, own agent plus the native Microsoft agent | Not covered by the SSO app |
Audit trail | Per-action logging tied to the HR source | Limited |
Watch-outs when connecting Namely to Microsoft Entra ID
A few Namely-specific details decide whether this connection stays reliable at scale.
No native inbound provisioning. Namely’s Entra gallery app is single sign-on only, so nothing creates, updates or disables accounts on its own. Joinly reads the Namely REST API and drives the full joiner/mover/leaver lifecycle, so the account behind the login is actually managed.
Mapping Groups and Group Types to Entra groups. Namely models structure through free-form Groups, Group Types, Departments and Divisions rather than a fixed hierarchy, so they don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from those structures to the correct groups and licences, so role drives access rather than manual assignment.
user_status and employee_type. Namely separates a profile’s user_status from its employee_type, and includes inactive and guest profiles. A naive rule can suspend or reactivate the wrong accounts. Joinly maps these states explicitly so only the intended profiles create, keep or lose an account.
Resolving the reports-to manager. The manager is stored as a reports-to reference to another Namely profile. Joinly resolves that link to the correct Entra ID account, so the manager attribute and any manager-based rules stay accurate.
UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, department code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Namely change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a digital media company with around 900 employees across three offices, running Namely as its HR core while its identity provisioning never quite keeps up. Namely’s Entra app handles single sign-on, but it doesn’t create or disable anything — so every new editor, producer or account manager still starts as a note that IT works through by hand in Entra ID, and freelancers and fixed-term contracts keep the queue full. New joiners regularly wait until day two for their account, and when someone moves between the Content and Brand teams their old group access lingers.
Connect Namely to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change in Namely at the source and acts on it automatically: new hires have their account, Microsoft 365 licence and group access ready on their start date, moves between teams swap the right groups the same day, inactive and guest profiles map to the correct account state, and leavers are disabled on their termination date with a 30-day soft-delete grace window.
“Single sign-on was never the problem — the account behind it was. Now an account is simply ready on the start date, a move just swaps the groups, and we can show exactly which Namely change created every bit of access.” — Head of IT, digital media company
The outcome this setup is designed for: onboarding drops from days to zero touch, privilege creep from old teams stops, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone Namely to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Namely to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the Namely integration in the Joinly marketplace
Open the Joinly marketplace and search for the Namely integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Namely integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Namely connection details: your Namely subdomain (the {subdomain}.namely.com part of your URL) and either an OAuth 2.0 connection or a Personal Access Token used as a Bearer token. In Namely you create the token under your profile icon → API → New Access Token. We only ask for the information needed to establish a successful connection with Namely. All data is encrypted and stored securely.

Enter your Namely subdomain and API credentials in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Namely profile fields.
Frequently asked questions
How do I map the manager? Reference the profile’s reports-to link in the mapping and Joinly resolves it to the right manager automatically.
How do I map Groups to Entra groups? Map Namely Groups, Group Types and departments to the target Entra groups; role then drives access.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map Namely fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Namely should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Namely flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the termination date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Namely to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Namely to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Namely reach Entra ID quickly without waiting for a nightly batch.
Doesn’t Namely already have an Entra / Azure AD integration?
Namely publishes an Entra gallery app, but it only handles single sign-on — it does not create, update or disable accounts. Joinly adds the HR-driven joiner, mover and leaver provisioning that the SSO app leaves out.
How does Joinly authenticate to Namely?
Through the Namely REST API, using either the OAuth 2.0 authorization-code flow or a Personal Access Token sent as a Bearer token, against your {subdomain}.namely.com endpoint over HTTPS.
Which attributes sync from Namely to Entra ID?
Name, email / UPN, department, job title, manager (reports to), Group membership, employee type, and start and end date. Custom Namely profile fields can be mapped via Liquid templates.
How are Namely Groups mapped to Entra ID groups?
Joinly builds explicit rules from Namely Groups, Group Types and departments to the correct Entra ID groups and licences, so a person’s role decides their access instead of manual assignment.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Namely to Active Directory guide.


