When someone joins, moves or leaves in PeopleStrong, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect PeopleStrong to Microsoft Entra ID, Joinly reads each HR change at the source — through the PeopleStrong REST API — and applies it automatically to the right account. PeopleStrong stays your source of truth; Joinly is the engine that keeps every action accurate and traceable.
Key takeaways
PeopleStrong stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically.
Joinly maps PeopleStrong’s own org model — Org Unit, Worksite and Entity — to the right Entra ID groups and licences, which the native API-driven path leaves entirely to you.
Joinly pulls from the PeopleStrong REST API with OAuth 2.0, using both the full-load and modified-data calls so no change is missed between runs.
Multi-entity, multi-country group structures are handled correctly, so a worker in one Entity and Worksite still gets the right groups from their Org Unit — a common failure point in APAC enterprise setups.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | PeopleStrong (core HCM) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | PeopleStrong REST API → Entra ID |
Supported events | Joiner, mover, leaver (incl. rehire, transfer between entities) |
Synced attributes | Name, email / UPN, department, job title, manager, Org Unit, Worksite, Entity, Employee Code, start and end date |
Authentication | OAuth 2.0 (client_id / client_secret, tenant token) |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync PeopleStrong to Microsoft Entra ID?
Joinly reads each HR change in PeopleStrong through its REST API and applies it to the matching Entra ID account automatically. PeopleStrong holds the authoritative employment record, so it is the starting point for each identity action.
Joiner. HR completes the hire in PeopleStrong. Joinly reads the new worker record — Org Unit, Worksite, Entity, job title and manager — and determines the role from those attributes. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups.
Mover. When someone changes Org Unit, Worksite or Entity in PeopleStrong, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual job.
Leaver. On the termination date recorded in PeopleStrong, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and a soft-delete grace window keeps the account recoverable before it is removed.
Example: An Indian retail group runs PeopleStrong across several store banners held under different Entities. It hires a category buyer for its Mumbai head office. Joinly reads the new record, creates the Entra ID account, assigns a Microsoft 365 licence and adds the buyer to the Merchandising group based on the Org Unit — while keeping the person tied to the correct Entity for reporting. When that buyer later transfers to a regional distribution Entity, Joinly swaps the groups the same day without breaking sign-in.
What manual user management costs
Without automation, every account starts as a PeopleStrong ticket or a line in a spreadsheet that IT works through by hand. Microsoft’s API-driven inbound provisioning can ingest data once you build and maintain the pipeline that pulls it from PeopleStrong, but it maps roles to groups through manual expression rules — so the part that actually decides access still falls to people.
Onboarding delays. New joiners wait for accounts, licences and group access while a ticket sits in a queue, losing productive days in their first week.
Permissions that don’t keep up (privilege creep). When movers change Org Unit, Worksite or Entity, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money.
Joinly vs. native Entra API-driven provisioning
Because PeopleStrong isn’t a pre-built Entra provisioning app, the native path is API-driven inbound provisioning — you build the pipeline that pulls PeopleStrong data and posts it to Microsoft Graph, then Entra applies mapping. Here’s how the two compare.
Joinly | Entra API-driven inbound provisioning | |
|---|---|---|
Source | Reads the PeopleStrong REST API directly | You build the pipeline that pulls PeopleStrong and posts to /bulkUpload |
Role-to-group mapping | Built in, rule-based on Org Unit / Worksite / Entity | Manual expression mappings; no role-to-group out of the box |
Multi-entity handling | Resolves Org Unit vs Entity vs Worksite explicitly | You must encode the logic in your own pipeline |
Full-load vs delta | Uses both the full-load and modified-data calls with reconciliation | You manage the pull cadence and de-duplication yourself |
Licence assignment | Driven by role / attributes | Manual or group-based only |
On-premise AD | Yes, own agent plus the native Microsoft agent | Provisioning agent required, limited mapping |
Audit trail | Per-action logging tied to the HR source | Limited |
Watch-outs when connecting PeopleStrong to Microsoft Entra ID
A few PeopleStrong-specific details decide whether this connection stays reliable at scale.
Multi-entity, multi-country group structures. In APAC enterprise deployments a worker can sit in one Entity and Worksite while reporting into an Org Unit somewhere else. A naive rule mixes these up and grants the wrong groups. Joinly maps Org Unit, Worksite and Entity as separate dimensions, so each one drives the right part of the access decision.
Request-only API access. PeopleStrong provisions API access per tenant on request, with OAuth 2.0 credentials scoped to that tenant. Joinly’s setup assumes those credentials and the tenant token, so the connection is authenticated correctly from the first run rather than falling back to fragile exports.
Full-load vs modified-data reconciliation. Relying only on the modified-data window can miss changes if a run is skipped or a record is backdated. Joinly combines the full-load and delta calls and reconciles them, so the Entra ID picture matches PeopleStrong even after an interruption.
Mapping Org Units to Entra groups. The PeopleStrong Org Unit hierarchy doesn’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from Org Unit, Worksite and Entity to the correct groups and licences, so role drives access rather than manual assignment.
UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, an Entity code or the Employee Code as a controlled tiebreaker — so every UPN is unique and predictable from day one.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which PeopleStrong change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture an Indian retail group with around 8,000 employees across several store banners, each held under a different Entity, running PeopleStrong as its HR core while identity provisioning never quite keeps up. Store staff turn over quickly, transfers between banners are constant, and every new hire starts as a PeopleStrong ticket that IT works through by hand — so a new store associate often waits days for their Microsoft 365 account and access to the merchandising tools.
Connect PeopleStrong to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change at the source and acts on it automatically: new hires have their account, licence and group access ready without a ticket, transfers between banners swap the right groups the same day while keeping the person tied to the correct Entity, and leavers are disabled on their termination date with a 30-day soft-delete grace window.
“With store staff turning over constantly, provisioning by hand was a losing battle. Now an account is simply ready when someone starts, a transfer just swaps the groups, and we can show exactly which PeopleStrong change created every bit of access.” — Head of IT, retail group
The outcome this setup is designed for: onboarding drops from days to zero touch, transfers between entities stop causing access gaps, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone PeopleStrong to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect PeopleStrong to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the PeopleStrong integration in the Joinly marketplace
Open the Joinly marketplace and search for the PeopleStrong integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the PeopleStrong integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your PeopleStrong connection details: your API base URL, tenant id and OAuth credentials (client_id and client_secret). Make sure API access has been enabled for your PeopleStrong tenant first, as access is granted on request. We only ask for the information needed to establish a successful connection with PeopleStrong. All data is encrypted and stored securely.

Enter your PeopleStrong API base URL, tenant id and OAuth credentials in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from PeopleStrong fields.
Frequently asked questions
How do I map the manager? Reference the manager’s Employee Code in the mapping and Joinly resolves the link to the right manager automatically.
How do I handle multiple entities? Map Org Unit, Worksite and Entity as separate inputs so each drives the right groups and reporting attributes.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map PeopleStrong fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from PeopleStrong should run, and whether each run uses the full-load or modified-data call.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in PeopleStrong flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the termination date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting PeopleStrong to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the PeopleStrong to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in PeopleStrong reach Entra ID quickly without waiting for a nightly batch.
How does Joinly connect to the PeopleStrong API?
Joinly reads PeopleStrong’s REST API using OAuth 2.0 (client_id and client_secret with your tenant token). API access is granted per tenant on request, so enable it for your PeopleStrong tenant before running the wizard.
How does Joinly handle multiple entities and worksites?
Joinly maps Org Unit, Worksite and Entity as separate dimensions, so a worker in one Entity or Worksite still gets the correct groups from their Org Unit without the dimensions being confused.
Which attributes sync from PeopleStrong to Entra ID?
Name, email / UPN, department, job title, manager, Org Unit, Worksite, Entity, Employee Code, and start and end date. Additional PeopleStrong fields can be mapped via Liquid templates.
Do I still need to build a native Entra API-driven provisioning pipeline?
No. Joinly takes over the PeopleStrong pull, the role-to-group mapping and the multi-entity handling that the native API-driven path leaves to you, and maintains it as your PeopleStrong data changes.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the PeopleStrong to Active Directory guide.


