Connect Namely to Microsoft Entra ID

Connect Namely to Microsoft Entra ID

Connect Namely to Microsoft Entra ID

When someone joins, moves or leaves in Namely, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Namely to Microsoft Entra ID, Joinly reads each HR change through the Namely REST API at the source and applies it automatically to the right account. Namely stays your source of truth; Joinly is the engine that keeps every action accurate and traceable — the piece Namely’s SSO-only Entra app leaves out.

Key takeaways

  • Namely stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically over the Namely REST API.

  • Namely’s own Entra/Azure AD gallery app is single sign-on only — it does not provision accounts — so Joinly fills the HR-driven joiner/mover/leaver gap.

  • Joinly maps Namely Groups, Group Types, Departments and Job Titles to the right Entra ID groups and licences, which SSO and generic SCIM setups can’t do on their own.

  • Joinly reads user_status and employee_type, so active, inactive and guest profiles drive the correct account state instead of a blunt on/off toggle.

  • Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.

Namely

Joiner

Mover

Leaver

Microsoft Entra ID (formerly Azure AD)

Quick facts

Source system

Namely (Namely HRIS)

Target system

Microsoft Entra ID (formerly Azure AD)

Connection method

Namely REST API → Entra ID

Supported events

Joiner, mover, leaver (incl. rehire and status changes)

Synced attributes

Name, email / UPN, department, job title, manager (reports to), group, employee type, start and end date

Authentication

OAuth 2.0 authorization code, or Personal Access Token (Bearer)

Real-time or batch

Frequent sync, multiple times per day

Compliance

ISO 27001, NIS2-ready, GDPR (EU data centre)

How does Joinly sync Namely to Microsoft Entra ID?

Joinly reads each HR change in Namely through the REST API and applies it to the matching Entra ID account automatically. Namely holds the authoritative employee record, so its Profiles endpoint is the starting point for every identity action.

  1. Joiner. HR completes the hire in Namely. Joinly reads the new profile — job title, department, the Groups the person belongs to and their reports-to manager — and determines the role from those attributes. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups, ready on the recorded start date.

  2. Mover. When someone’s job title, department or Group membership changes in Namely, Joinly updates their Entra ID group membership, permissions and licences to match. Access that no longer fits the new role is revoked, so permissions stay aligned with the actual job.

  3. Leaver. When a profile’s user_status changes to an inactive status on the termination date in Namely, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and rehires are matched back to the existing account instead of creating a duplicate.

Example: A digital media company hires a video editor in Namely, in its Content department, with a start date next Monday. Joinly reads the profile, waits until the start date, creates the Entra ID account, assigns a Microsoft 365 E3 licence and adds the editor to the Content-Production group based on their Namely Group. When that editor later moves into the Brand team, Joinly swaps the group membership the same day, without anyone opening a ticket.

What manual user management costs

Without automation, every account starts as a Namely note or a line in a spreadsheet that IT works through by hand. Namely’s Entra gallery app only covers single sign-on, and generic SCIM or third-party connectors move a few attributes across but map roles to groups by hand — so the part that actually decides access still falls to people.

  • Onboarding delays. New joiners wait for accounts, licences and group access while a request sits in a queue, losing productive days in their first week.

  • Permissions that don’t keep up (privilege creep). When movers change job title, department or Group in Namely, old access often stays attached, so people accumulate rights they no longer need.

  • Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — and an SSO-only setup does nothing to deprovision the account behind the login.

Joinly vs. Namely’s native Entra options

Namely publishes an Entra/Azure AD gallery app for single sign-on, but there is no first-party inbound provisioning connector — so the alternative is Microsoft’s generic API-driven / SCIM inbound provisioning or a third-party SSO tool. Here’s how the two compare for a Namely-driven setup.


Joinly

Namely SSO app / generic SCIM

Source

Reads the Namely REST API directly

SSO only; provisioning needs a separate SCIM bridge

Role-to-group mapping

Built in, rule-based on Groups, departments and job titles

Manual attribute mapping; no role-to-group out of the box

Joiner / mover / leaver

Full HR-driven lifecycle from Namely

SSO does not create, move or disable accounts

Status / employee type

Maps user_status and employee_type to account state

Blunt active/inactive toggle at best

Licence assignment

Driven by role / attributes

Manual or group-based only

On-premise AD

Yes, own agent plus the native Microsoft agent

Not covered by the SSO app

Audit trail

Per-action logging tied to the HR source

Limited

Watch-outs when connecting Namely to Microsoft Entra ID

A few Namely-specific details decide whether this connection stays reliable at scale.

  • No native inbound provisioning. Namely’s Entra gallery app is single sign-on only, so nothing creates, updates or disables accounts on its own. Joinly reads the Namely REST API and drives the full joiner/mover/leaver lifecycle, so the account behind the login is actually managed.

  • Mapping Groups and Group Types to Entra groups. Namely models structure through free-form Groups, Group Types, Departments and Divisions rather than a fixed hierarchy, so they don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from those structures to the correct groups and licences, so role drives access rather than manual assignment.

  • user_status and employee_type. Namely separates a profile’s user_status from its employee_type, and includes inactive and guest profiles. A naive rule can suspend or reactivate the wrong accounts. Joinly maps these states explicitly so only the intended profiles create, keep or lose an account.

  • Resolving the reports-to manager. The manager is stored as a reports-to reference to another Namely profile. Joinly resolves that link to the correct Entra ID account, so the manager attribute and any manager-based rules stay accurate.

  • UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, department code or controlled tiebreaker — so every UPN is unique and predictable from day one.

Joinly handles each of these by default with custom mapping and transformation.

Always audit-ready

Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Namely change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.

Example case

Picture a digital media company with around 900 employees across three offices, running Namely as its HR core while its identity provisioning never quite keeps up. Namely’s Entra app handles single sign-on, but it doesn’t create or disable anything — so every new editor, producer or account manager still starts as a note that IT works through by hand in Entra ID, and freelancers and fixed-term contracts keep the queue full. New joiners regularly wait until day two for their account, and when someone moves between the Content and Brand teams their old group access lingers.

Connect Namely to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change in Namely at the source and acts on it automatically: new hires have their account, Microsoft 365 licence and group access ready on their start date, moves between teams swap the right groups the same day, inactive and guest profiles map to the correct account state, and leavers are disabled on their termination date with a 30-day soft-delete grace window.

“Single sign-on was never the problem — the account behind it was. Now an account is simply ready on the start date, a move just swaps the groups, and we can show exactly which Namely change created every bit of access.” — Head of IT, digital media company

The outcome this setup is designed for: onboarding drops from days to zero touch, privilege creep from old teams stops, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.

More than a connector

A standalone Namely to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.

Schedule a demo

Installation manual

Installation manual

Connect Namely to Microsoft Entra ID

Connect Namely to Microsoft Entra ID

Installation guide

Follow these steps to connect Namely to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.

1. Create your account

Go to platform.joinly.app and create your account.

Note: charges may apply for using the platform after the trial period ends.


Joinly account creation screen at platform.joinly.app


Sign up at platform.joinly.app to get started.

2. Connect your Microsoft account

Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.


Joinly identity provider setup screen for connecting a Microsoft Entra tenant


Connect your Microsoft tenant and pick your scopes.

3. Import your existing accounts from Entra ID

Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.

4. Find the Namely integration in the Joinly marketplace

Open the Joinly marketplace and search for the Namely integration.

Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.


Joinly marketplace showing available HR integrations


Search the marketplace for the Namely integration.

5. Follow the installation wizard

You may be redirected to integrations.joinly.app. Create an account there and enter your Namely connection details: your Namely subdomain (the {subdomain}.namely.com part of your URL) and either an OAuth 2.0 connection or a Personal Access Token used as a Bearer token. In Namely you create the token under your profile icon → API → New Access Token. We only ask for the information needed to establish a successful connection with Namely. All data is encrypted and stored securely.


Joinly installation wizard for entering Namely connection details


Enter your Namely subdomain and API credentials in the wizard.

6. Configure your field mapping

Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Namely profile fields.

Frequently asked questions

  • How do I map the manager? Reference the profile’s reports-to link in the mapping and Joinly resolves it to the right manager automatically.

  • How do I map Groups to Entra groups? Map Namely Groups, Group Types and departments to the target Entra groups; role then drives access.

  • How do I prevent duplicate usernames? Use the generateUniqueUsername helper, which falls back to the next pattern when the first one is already taken:
    {{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}


Joinly field mapping screen for Namely attributes using Liquid templates


Map Namely fields to Entra ID attributes with Liquid templates.

7. Configure the scheduled import

At platform.joinly.app/settings/import-configs, configure how often the import from Namely should run.

8. Configure your workflows

Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Namely flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the termination date (for example 30 days) to retire accounts safely.


Joinly workflow editor creating an employee onboarding workflow


Create a trigger-based onboarding workflow.


Adding the create or update employee in Entra action to a workflow


Add the create/update action, then set your matching strategy and field mapping.


Adding the Entra soft delete action to remove accounts on employee leave


Add the Entra soft delete action to retire accounts safely.

## AD on-premise support

Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Namely to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.

Frequently asked questions

Does the Namely to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Namely reach Entra ID quickly without waiting for a nightly batch.

Doesn’t Namely already have an Entra / Azure AD integration?
Namely publishes an Entra gallery app, but it only handles single sign-on — it does not create, update or disable accounts. Joinly adds the HR-driven joiner, mover and leaver provisioning that the SSO app leaves out.

How does Joinly authenticate to Namely?
Through the Namely REST API, using either the OAuth 2.0 authorization-code flow or a Personal Access Token sent as a Bearer token, against your {subdomain}.namely.com endpoint over HTTPS.

Which attributes sync from Namely to Entra ID?
Name, email / UPN, department, job title, manager (reports to), Group membership, employee type, and start and end date. Custom Namely profile fields can be mapped via Liquid templates.

How are Namely Groups mapped to Entra ID groups?
Joinly builds explicit rules from Namely Groups, Group Types and departments to the correct Entra ID groups and licences, so a person’s role decides their access instead of manual assignment.

Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Namely to Active Directory guide.

Request installation support