Connect Paychex Flex to Microsoft Entra ID

Connect Paychex Flex to Microsoft Entra ID

Connect Paychex Flex to Microsoft Entra ID

When someone joins, moves or leaves in Paychex Flex, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Paychex Flex to Microsoft Entra ID, Joinly reads each worker change at the source — through the Paychex Flex API — and applies it automatically to the right account. Paychex Flex stays your source of truth; Joinly is the engine that keeps every action accurate and traceable, even when there’s no IT team watching it.

Key takeaways

  • Paychex Flex stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically — true zero-touch, which matters most when there’s no IT department to run a manual process.

  • Joinly maps Paychex Flex structure — company, division, branch, department, location and job title — to the right Entra ID groups and licences. The native Paychex Flex Entra app does single sign-on only and provisions nothing.

  • Joinly reads the full worker across the Paychex Flex API’s separate worker, job, organization and communications endpoints, so the account is built from complete data, not a half-empty base record.

  • Frequent small structural changes — a new department, a renamed location, a status flip to leave — are picked up on the next sync and applied automatically.

  • Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.

Paychex Flex

Joiner

Mover

Leaver

Microsoft Entra ID (formerly Azure AD)

Quick facts

Source system

Paychex Flex

Target system

Microsoft Entra ID (formerly Azure AD)

Connection method

Paychex Flex API (OAuth 2.0) → Entra ID

Supported events

Joiner, mover, leaver (incl. rehire, status change to leave, department move)

Synced attributes

Name, email / UPN, department, division, location, job title, supervisor, worker type, hire and termination date

Authentication

OAuth 2.0 (client_credentials) with workers:read / workers:write scopes

Real-time or batch

Frequent sync, multiple times per day

Compliance

ISO 27001, NIS2-ready, GDPR (EU data centre)

How does Joinly sync Paychex Flex to Microsoft Entra ID?

Joinly reads each worker change in Paychex Flex through the Paychex Flex API and applies it to the matching Entra ID account automatically. Paychex Flex holds the authoritative worker record, so it is the starting point for each identity action — and once it’s set up, no one on your side has to touch it.

  1. Joiner. A new hire is added in Paychex Flex. Joinly reads the worker across the API’s separate endpoints — the base worker, the job, the organization assignment and the communications (email) — and determines the role from department, location and job title. It then creates the Entra ID account, assigns the right Microsoft 365 licences and adds the person to the correct groups, timed to the hire date.

  2. Mover. When a worker changes department, location or supervisor in Paychex Flex, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new role is revoked, so permissions stay aligned with the actual job — even though these moves happen in small, frequent batches with no one tracking them manually.

  3. Leaver. When a worker’s status flips to terminated on their termination date in Paychex Flex, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and no unused licences quietly billing every month.

Example: A 40-person accounting firm runs Paychex Flex and Microsoft 365. It hires a junior auditor with a hire date next Monday in its Tax department. Joinly reads the worker, waits until the hire date, creates the Entra ID account, assigns a Business Premium licence and adds the auditor to the Tax-Staff group. When the firm later spins up a new ‘Advisory’ department and moves three people into it, Joinly picks up the new department on the next sync and swaps each person’s groups without anyone editing Entra ID by hand.

What manual user management costs

Without automation, every account starts as a note from the office manager or a line in a spreadsheet that someone works through by hand — and in a small Paychex Flex shop, that ‘someone’ usually isn’t an IT specialist. The native Paychex Flex Entra app only does single sign-on, so account creation, licences and group access are entirely manual, and Entra ID’s own SCIM provisioning needs a Premium P1/P2 licence per user that small clients rarely have.

  • Onboarding delays. New joiners wait for accounts, licences and group access while the office manager finds time between other work, losing productive days in their first week.

  • Permissions that don’t keep up (privilege creep). When workers move department or location, old access often stays attached, so people accumulate rights they no longer need — and with no IT review, no one catches it.

  • Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused Microsoft 365 licences keep costing money every month after someone has gone.

Joinly vs. the native Paychex Flex options

The Paychex Flex Entra gallery app is single sign-on only — it provisions nothing. Buyers usually compare Joinly against third-party connectors (RoboMQ Hire2Retire, Aquera) or Entra ID’s own SCIM. Here’s how the options stack up for a small Paychex Flex client.


Joinly

Paychex Flex gallery app / Entra SCIM

Provisioning

Full joiner-mover-leaver from Paychex Flex

SSO only (gallery app); SCIM needs Premium P1/P2

Source

Reads the Paychex Flex API directly

No native read; SSO assertion only

Full worker record

Joins worker, job, organization and email endpoints

n/a — no provisioning

Department-to-group mapping

Built in, rule-based on Paychex Flex structure

Manual or not available

Licence assignment

Driven by role / attributes

Manual

Fits a no-IT shop

Zero-touch once configured

Needs manual admin or Premium licensing

Audit trail

Per-action logging tied to the HR source

Limited

Watch-outs when connecting Paychex Flex to Microsoft Entra ID

A few Paychex Flex-specific details decide whether this connection stays reliable in a small organisation with no dedicated IT.

  • No IT team to babysit the sync. Most Paychex Flex clients are small businesses without a dedicated admin or middleware. A sync that needs hand-holding will quietly fail. Joinly runs zero-touch in the cloud after setup, so the chain keeps working without anyone watching it.

  • The worker is split across several API endpoints. The Paychex Flex API returns the base worker, the job, the organization assignment and the email on separate endpoints. A naive integration that reads only the base worker provisions an account with no department or email. Joinly joins all the endpoints into one complete record before it acts.

  • Flat structure, frequent small changes. Small orgs have a handful of departments and locations that change often in ad-hoc ways — a new department, a renamed branch, a status set to leave. Joinly maps that structure to Entra groups with explicit rules and picks up each change on the next sync.

  • Worker status nuances. Paychex Flex distinguishes active, leave and terminated. A worker on leave should keep an account; a terminated one should not. Joinly maps each status to the right Entra action so a temporary leave never disables a live account.

  • UPN format with duplicate names. In a small firm, two people sharing a first name is common. Joinly applies custom transformation rules — a suffix or controlled tiebreaker — so every UPN is unique and predictable from day one.

Joinly handles each of these by default with custom mapping and transformation.

Always audit-ready

Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Paychex Flex change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request from the office manager. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.

Example case

Picture a 40-person accounting firm running Paychex Flex for payroll and Microsoft 365 for everything else, with no IT department — the office manager handles new accounts between client deadlines. New auditors wait until day two or three for their login, leavers keep an active mailbox for weeks, and at tax season the temporary hires double the backlog. The native Paychex Flex Entra app only signs people in; it never creates the account in the first place.

Connect Paychex Flex to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each worker change at the source and acts on it automatically: new hires have their account, Business Premium licence and group access ready on their hire date, a move into the new Advisory department swaps groups the same day, a status set to leave is handled correctly, and terminations disable the account on the termination date with a 30-day soft-delete grace window — all without anyone on staff touching Entra ID.

“We don’t have an IT person, so ‘set it and forget it’ was the only option that worked. Now an auditor’s account is simply ready on their first day, and at the next review we can show exactly which Paychex change created every login.” — Managing Partner, accounting firm

The outcome this setup is designed for: onboarding drops from days to zero touch, no one chases the office manager for a login, and the firm can show a complete, source-backed audit trail without ever hiring an IT admin.

More than a connector

A standalone Paychex Flex to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.

Schedule a demo

Installation manual

Installation manual

Connect Paychex Flex to Microsoft Entra ID

Connect Paychex Flex to Microsoft Entra ID

Installation guide

Follow these steps to connect Paychex Flex to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required — which is exactly what a small office without IT needs.

1. Create your account

Go to platform.joinly.app and create your account.

Note: charges may apply for using the platform after the trial period ends.


Joinly account creation screen at platform.joinly.app


Sign up at platform.joinly.app to get started.

2. Connect your Microsoft account

Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.


Joinly identity provider setup screen for connecting a Microsoft Entra tenant


Connect your Microsoft tenant and pick your scopes.

3. Import your existing accounts from Entra ID

Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.

4. Find the Paychex Flex integration in the Joinly marketplace

Open the Joinly marketplace and search for the Paychex Flex integration.

Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.


Joinly marketplace showing available HR integrations


Search the marketplace for the Paychex Flex integration.

5. Follow the installation wizard

You may be redirected to integrations.joinly.app. Create an account there and enter your Paychex Flex connection details: your OAuth 2.0 client ID and client secret from the Paychex Developer Center, and your company ID. We only ask for the information needed to establish a successful connection with Paychex Flex. All data is encrypted and stored securely.


Joinly installation wizard for entering Paychex Flex connection details


Enter your Paychex Flex OAuth client credentials and company ID in the wizard.

6. Configure your field mapping

Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Paychex Flex worker, job and organization fields.

Frequently asked questions

  • How do I map the supervisor? Reference the supervisor on the worker record and Joinly resolves the link to the right manager automatically.

  • How do I get the worker’s email and department? Joinly reads the separate communications and organization endpoints and merges them into the worker, so you can map them like any other field.

  • How do I prevent duplicate usernames? Use the generateUniqueUsername helper, which falls back to the next pattern when the first one is already taken:
    {{ generateUniqueUsername: “{firstName}.{lastName}”, “{firstName}.{initial}.{lastName}” }}


Joinly field mapping screen for Paychex Flex attributes using Liquid templates


Map Paychex Flex fields to Entra ID attributes with Liquid templates.

7. Configure the scheduled import

At platform.joinly.app/settings/import-configs, configure how often the import from Paychex Flex should run.

8. Configure your workflows

Workflows are where Joinly turns each worker change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Paychex Flex flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the termination date (for example 30 days) to retire accounts safely.


Joinly workflow editor creating an employee onboarding workflow


Create a trigger-based onboarding workflow.


Adding the create or update employee in Entra action to a workflow


Add the create/update action, then set your matching strategy and field mapping.


Adding the Entra soft delete action to remove accounts on employee leave


Add the Entra soft delete action to retire accounts safely.

## AD on-premise support

Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Paychex Flex to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.

Frequently asked questions

Does the Paychex Flex to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Paychex Flex reach Entra ID quickly without waiting for a nightly batch.

We don’t have an IT team — can we still use this?
Yes, that’s exactly who it’s for. The whole setup is cloud-based with no scripts or local software, and once configured it runs zero-touch, so no one on staff has to manage accounts by hand.

Does Joinly read the full Paychex Flex worker record?
Yes. The Paychex Flex API splits a worker across separate worker, job, organization and communications endpoints; Joinly reads them all and merges them, so the account is built from a complete record including department and email.

Which attributes sync from Paychex Flex to Entra ID?
Name, email / UPN, department, division, location, job title, supervisor, worker type, and hire and termination date. Other Paychex Flex fields can be mapped via Liquid templates.

Do I still need the native Paychex Flex Entra app or Entra SCIM?
The native gallery app only does single sign-on and doesn’t provision anyone, and Entra’s own SCIM needs a Premium licence per user. Joinly takes over the actual provisioning, mapping and offboarding the native options don’t cover.

Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Paychex Flex to Active Directory guide.

Request installation support