When someone joins, moves or leaves in Paychex Flex, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Paychex Flex to Microsoft Entra ID, Joinly reads each worker change at the source — through the Paychex Flex API — and applies it automatically to the right account. Paychex Flex stays your source of truth; Joinly is the engine that keeps every action accurate and traceable, even when there’s no IT team watching it.
Key takeaways
Paychex Flex stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically — true zero-touch, which matters most when there’s no IT department to run a manual process.
Joinly maps Paychex Flex structure — company, division, branch, department, location and job title — to the right Entra ID groups and licences. The native Paychex Flex Entra app does single sign-on only and provisions nothing.
Joinly reads the full worker across the Paychex Flex API’s separate worker, job, organization and communications endpoints, so the account is built from complete data, not a half-empty base record.
Frequent small structural changes — a new department, a renamed location, a status flip to leave — are picked up on the next sync and applied automatically.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | Paychex Flex |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Paychex Flex API (OAuth 2.0) → Entra ID |
Supported events | Joiner, mover, leaver (incl. rehire, status change to leave, department move) |
Synced attributes | Name, email / UPN, department, division, location, job title, supervisor, worker type, hire and termination date |
Authentication | OAuth 2.0 (client_credentials) with workers:read / workers:write scopes |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Paychex Flex to Microsoft Entra ID?
Joinly reads each worker change in Paychex Flex through the Paychex Flex API and applies it to the matching Entra ID account automatically. Paychex Flex holds the authoritative worker record, so it is the starting point for each identity action — and once it’s set up, no one on your side has to touch it.
Joiner. A new hire is added in Paychex Flex. Joinly reads the worker across the API’s separate endpoints — the base worker, the job, the organization assignment and the communications (email) — and determines the role from department, location and job title. It then creates the Entra ID account, assigns the right Microsoft 365 licences and adds the person to the correct groups, timed to the hire date.
Mover. When a worker changes department, location or supervisor in Paychex Flex, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new role is revoked, so permissions stay aligned with the actual job — even though these moves happen in small, frequent batches with no one tracking them manually.
Leaver. When a worker’s status flips to terminated on their termination date in Paychex Flex, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and no unused licences quietly billing every month.
Example: A 40-person accounting firm runs Paychex Flex and Microsoft 365. It hires a junior auditor with a hire date next Monday in its Tax department. Joinly reads the worker, waits until the hire date, creates the Entra ID account, assigns a Business Premium licence and adds the auditor to the Tax-Staff group. When the firm later spins up a new ‘Advisory’ department and moves three people into it, Joinly picks up the new department on the next sync and swaps each person’s groups without anyone editing Entra ID by hand.
What manual user management costs
Without automation, every account starts as a note from the office manager or a line in a spreadsheet that someone works through by hand — and in a small Paychex Flex shop, that ‘someone’ usually isn’t an IT specialist. The native Paychex Flex Entra app only does single sign-on, so account creation, licences and group access are entirely manual, and Entra ID’s own SCIM provisioning needs a Premium P1/P2 licence per user that small clients rarely have.
Onboarding delays. New joiners wait for accounts, licences and group access while the office manager finds time between other work, losing productive days in their first week.
Permissions that don’t keep up (privilege creep). When workers move department or location, old access often stays attached, so people accumulate rights they no longer need — and with no IT review, no one catches it.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused Microsoft 365 licences keep costing money every month after someone has gone.
Joinly vs. the native Paychex Flex options
The Paychex Flex Entra gallery app is single sign-on only — it provisions nothing. Buyers usually compare Joinly against third-party connectors (RoboMQ Hire2Retire, Aquera) or Entra ID’s own SCIM. Here’s how the options stack up for a small Paychex Flex client.
Joinly | Paychex Flex gallery app / Entra SCIM | |
|---|---|---|
Provisioning | Full joiner-mover-leaver from Paychex Flex | SSO only (gallery app); SCIM needs Premium P1/P2 |
Source | Reads the Paychex Flex API directly | No native read; SSO assertion only |
Full worker record | Joins worker, job, organization and email endpoints | n/a — no provisioning |
Department-to-group mapping | Built in, rule-based on Paychex Flex structure | Manual or not available |
Licence assignment | Driven by role / attributes | Manual |
Fits a no-IT shop | Zero-touch once configured | Needs manual admin or Premium licensing |
Audit trail | Per-action logging tied to the HR source | Limited |
Watch-outs when connecting Paychex Flex to Microsoft Entra ID
A few Paychex Flex-specific details decide whether this connection stays reliable in a small organisation with no dedicated IT.
No IT team to babysit the sync. Most Paychex Flex clients are small businesses without a dedicated admin or middleware. A sync that needs hand-holding will quietly fail. Joinly runs zero-touch in the cloud after setup, so the chain keeps working without anyone watching it.
The worker is split across several API endpoints. The Paychex Flex API returns the base worker, the job, the organization assignment and the email on separate endpoints. A naive integration that reads only the base worker provisions an account with no department or email. Joinly joins all the endpoints into one complete record before it acts.
Flat structure, frequent small changes. Small orgs have a handful of departments and locations that change often in ad-hoc ways — a new department, a renamed branch, a status set to leave. Joinly maps that structure to Entra groups with explicit rules and picks up each change on the next sync.
Worker status nuances. Paychex Flex distinguishes active, leave and terminated. A worker on leave should keep an account; a terminated one should not. Joinly maps each status to the right Entra action so a temporary leave never disables a live account.
UPN format with duplicate names. In a small firm, two people sharing a first name is common. Joinly applies custom transformation rules — a suffix or controlled tiebreaker — so every UPN is unique and predictable from day one.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Paychex Flex change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request from the office manager. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a 40-person accounting firm running Paychex Flex for payroll and Microsoft 365 for everything else, with no IT department — the office manager handles new accounts between client deadlines. New auditors wait until day two or three for their login, leavers keep an active mailbox for weeks, and at tax season the temporary hires double the backlog. The native Paychex Flex Entra app only signs people in; it never creates the account in the first place.
Connect Paychex Flex to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each worker change at the source and acts on it automatically: new hires have their account, Business Premium licence and group access ready on their hire date, a move into the new Advisory department swaps groups the same day, a status set to leave is handled correctly, and terminations disable the account on the termination date with a 30-day soft-delete grace window — all without anyone on staff touching Entra ID.
“We don’t have an IT person, so ‘set it and forget it’ was the only option that worked. Now an auditor’s account is simply ready on their first day, and at the next review we can show exactly which Paychex change created every login.” — Managing Partner, accounting firm
The outcome this setup is designed for: onboarding drops from days to zero touch, no one chases the office manager for a login, and the firm can show a complete, source-backed audit trail without ever hiring an IT admin.
More than a connector
A standalone Paychex Flex to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Paychex Flex to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required — which is exactly what a small office without IT needs.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the Paychex Flex integration in the Joinly marketplace
Open the Joinly marketplace and search for the Paychex Flex integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Paychex Flex integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Paychex Flex connection details: your OAuth 2.0 client ID and client secret from the Paychex Developer Center, and your company ID. We only ask for the information needed to establish a successful connection with Paychex Flex. All data is encrypted and stored securely.

Enter your Paychex Flex OAuth client credentials and company ID in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Paychex Flex worker, job and organization fields.
Frequently asked questions
How do I map the supervisor? Reference the supervisor on the worker record and Joinly resolves the link to the right manager automatically.
How do I get the worker’s email and department? Joinly reads the separate communications and organization endpoints and merges them into the worker, so you can map them like any other field.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{lastName}”, “{firstName}.{initial}.{lastName}” }}

Map Paychex Flex fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Paychex Flex should run.
8. Configure your workflows
Workflows are where Joinly turns each worker change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Paychex Flex flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the termination date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Paychex Flex to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Paychex Flex to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Paychex Flex reach Entra ID quickly without waiting for a nightly batch.
We don’t have an IT team — can we still use this?
Yes, that’s exactly who it’s for. The whole setup is cloud-based with no scripts or local software, and once configured it runs zero-touch, so no one on staff has to manage accounts by hand.
Does Joinly read the full Paychex Flex worker record?
Yes. The Paychex Flex API splits a worker across separate worker, job, organization and communications endpoints; Joinly reads them all and merges them, so the account is built from a complete record including department and email.
Which attributes sync from Paychex Flex to Entra ID?
Name, email / UPN, department, division, location, job title, supervisor, worker type, and hire and termination date. Other Paychex Flex fields can be mapped via Liquid templates.
Do I still need the native Paychex Flex Entra app or Entra SCIM?
The native gallery app only does single sign-on and doesn’t provision anyone, and Entra’s own SCIM needs a Premium licence per user. Joinly takes over the actual provisioning, mapping and offboarding the native options don’t cover.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Paychex Flex to Active Directory guide.


