When someone joins, moves or leaves in Remote, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Remote to Microsoft Entra ID, Joinly reads each employment change at the source — through the Remote API — and applies it automatically to the right account. Remote stays your source of truth for EOR employees, direct employees and contractors alike; Joinly is the engine that keeps every action accurate and traceable.
Key takeaways
Remote stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically from the Remote API.
Joinly tells EOR employees, direct (Global Payroll) employees and contractors apart by employment_type, so each worker type becomes the right kind of Entra ID account — not one blanket rule.
Multi-country and multi-entity workforces are handled per legal entity, so UPN, licence and group rules key off the actual country and entity instead of a single global default.
Joinly acts on the Remote employment lifecycle — provisioning on the move to ‘active’ and disabling when the record moves to ‘archived’ on the termination date — rather than the moment a record is first created.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | Remote (Remote HR) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Remote API (REST) → Entra ID |
Supported events | Joiner, mover, leaver (incl. EOR employees, direct employees and contractors) |
Synced attributes | Name, email / UPN, job title, department, manager, legal entity, country, employment type, start and end date |
Authentication | OAuth 2.0 bearer token (ra_live_) generated in Company Settings → Integrations & APIs |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Remote to Microsoft Entra ID?
Joinly reads each employment change in Remote through the Remote API and applies it to the matching Entra ID account automatically. Remote holds the authoritative employment record — for EOR employees, direct-payroll employees and contractors — so it is the starting point for each identity action.
Joiner. HR completes the hire in Remote and the employment moves through its lifecycle to an active status. Joinly reads the new employment record, determines the role from attributes like job title, department, country and legal entity, and checks the employment_type. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the start of active employment rather than the moment the record was first created.
Mover. When someone changes job title, department, country or legal entity in Remote — or converts from contractor to EOR employee — Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual role.
Leaver. When a Remote employment reaches its termination_date and the status moves to ‘archived’, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left, and because a person can hold more than one engagement, access is only removed when their last active employment ends.
Example: A distributed SaaS company hires a support engineer in Colombia as an EOR employee, with a start date next Monday. Joinly reads the Remote employment, waits until it becomes active, creates the Entra ID account, assigns a Microsoft 365 E3 licence and adds the engineer to the Support-LATAM group. A month later a marketing contractor in Portugal is converted to a direct employee under Remote Global Payroll; Joinly sees the employment_type change and swaps the account from a limited contractor profile to a full-employee group set without creating a duplicate.
What manual user management costs
Without automation, every account starts as a note from HR or a line exported from Remote that IT works through by hand. You can pull the Remote API into a CSV or a PowerShell script, but that leaves the part that actually decides access — which worker type gets which account, which country drives the UPN, which role maps to which group — to people, and it drifts the moment the workforce changes.
Onboarding delays. New joiners wait for accounts, licences and group access while a request sits in a queue, losing productive days in their first week — and cross-border EOR hires are exactly the ones most likely to fall through the cracks.
Permissions that don’t keep up (privilege creep). When people change role, country or convert from contractor to employee, old access often stays attached, so they accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — easy to miss when an offboarding in Remote is just one status change among many countries.
Joinly vs. a scripted Remote API integration
Remote’s own integrations point inward — it syncs natively with HRIS and finance tools like Workday, HiBob, BambooHR and Personio — but it doesn’t ship a role-to-group provisioning connector to Entra ID. So the realistic alternative is a home-grown script against the Remote API. Here’s how the two compare.
Joinly | Scripted Remote API / CSV pull | |
|---|---|---|
Source | Reads the Remote API directly | Reads the Remote API directly |
Worker-type handling | Splits EOR employees, direct employees and contractors by employment_type | Hand-coded filters that break on new types |
Role-to-group mapping | Built in, rule-based on role, department and legal entity | Custom code you write and maintain |
Multi-country / entity | UPN and group rules keyed per legal entity | Single global rule or a growing pile of exceptions |
Lifecycle timing | Acts on the active / archived transition | Fires on record creation unless you build the logic |
On-premise AD | Yes, own agent plus the native Microsoft agent | More scripting against a domain controller |
Audit trail | Per-action logging tied to the HR source | Whatever your script happens to log |
Watch-outs when connecting Remote to Microsoft Entra ID
A few Remote-specific details decide whether this connection stays reliable across countries and worker types.
Mixed worker types in one tenant. EOR employees, direct-payroll employees and contractors all live under the same Remote company but shouldn’t all become the same Entra ID account — a contractor rarely needs a full licence and internal groups. Joinly reads employment_type and applies a different account profile to each, so classification drives access.
Multi-country and multi-entity workforces. Remote owns a legal entity in each country it operates in, and country decides which fields are populated. A single global UPN or group rule breaks the moment you hire in a new country. Joinly keys UPN, licence and group rules off the legal entity and country so every account is correct wherever the person sits.
Employment lifecycle timing. A Remote hire moves through ‘created’ and ‘invited’ during self-enrollment before it becomes ‘active’, and only flips to ‘archived’ when the termination_date passes. Provisioning on record creation gives people access before they’ve onboarded. Joinly acts on the lifecycle transition, so the account is ready when employment goes active and disabled when it is archived.
Contractor-to-employee conversions. When a contractor converts to an EOR or direct employee, a naive sync can leave a stale contractor account alongside a new employee one. Joinly matches on the person and upgrades the existing account in place, so there is no duplicate.
UPN format across countries and duplicate names. A large, distributed workforce means name collisions and inconsistent local formats. Joinly applies custom transformation rules — a suffix, country or legal-entity code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Remote change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a distributed SaaS company with around 700 people across 30-odd countries, running Remote as its HR core — a mix of EOR employees, a handful of direct employees where it owns a local entity, and a steady rotation of contractors. IT provisions Entra ID from a monthly Remote export dropped into a script, and it never quite keeps up: contractors end up with the same licences and internal groups as full employees, a new hire in a new country breaks the UPN rule, and people who converted from contractor to employee carry two accounts.
Connect Remote to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each employment change in Remote at the source and acts on it automatically: EOR employees get their account, Microsoft 365 licence and groups the day they go active, contractors get a deliberately limited profile, conversions upgrade the existing account in place, UPNs stay unique per legal entity, and leavers are disabled when their employment is archived on the termination date.
“We hire in a new country most months, and the old export-and-script routine broke every time. Now a support engineer in Colombia is ready on day one, a contractor never gets an employee’s access by accident, and we can show exactly which Remote change created every account.” — Head of IT, distributed SaaS company
The outcome this setup is designed for: onboarding drops from days to zero touch across every country, contractors and employees stop being treated the same, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone Remote to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Remote to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Generate your Remote API token
In Remote, a company admin or owner goes to Company → Company Settings → Integrations & APIs → Integrations, opens the Remote API card and clicks Generate API token. Use a production (ra_live_) token. Keep it safe — you’ll paste it into the Joinly wizard in the next steps.
Don’t see the option? Only company admins and owners can create or revoke API tokens.
5. Find the Remote integration in the Joinly marketplace
Open the Joinly marketplace and search for the Remote integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Remote integration.
6. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Remote connection details: paste the ra_live_ API token you generated. We only ask for the information needed to establish a successful connection with Remote. All data is encrypted and stored securely.

Enter your Remote API token in the wizard.
7. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Remote fields.
Frequently asked questions
How do I handle different worker types? Branch on
employment_typeso EOR employees, direct employees and contractors each get the right account profile and groups.How do I set the UPN per country? Reference the legal entity or country in the template so the UPN and domain match where the person actually sits.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map Remote fields to Entra ID attributes with Liquid templates.
8. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Remote should run.
9. Configure your workflows
Workflows are where Joinly turns each employment change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Remote flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the termination date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Remote to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Remote to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Remote reach Entra ID quickly without waiting for a nightly batch.
How does Joinly handle EOR employees, direct employees and contractors?
Joinly reads the employment_type on each Remote employment and applies a different account profile to each — a full account and groups for EOR and direct employees, a deliberately limited profile for contractors — so a worker’s classification drives the access they get.
How does Joinly deal with hires across many countries?
Remote owns a legal entity in each country it operates in, and Joinly keys the UPN, licence and group rules off that legal entity and country, so every account is correct wherever the person is hired rather than following one global default.
Which attributes sync from Remote to Entra ID?
Name, email / UPN, job title, department, manager, legal entity, country, employment type, and start and end date. Additional Remote fields can be mapped via Liquid templates.
Do I still need a custom script against the Remote API?
No. Joinly takes over the provisioning, worker-type handling and role-to-group mapping you’d otherwise hand-code against the Remote API, and maintains it as your Remote data changes.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Remote to Active Directory guide.


