When someone joins, moves or leaves in Simployer, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect Simployer to Microsoft Entra ID, Joinly reads each HR change from Simployer One at the source — through the Simployer HR Connect API — and applies it automatically to the right account. Simployer stays your source of truth; Joinly is the engine that keeps every action accurate and traceable.
Key takeaways
Simployer One stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically.
Joinly reads Simployer’s own structure — organization, company, department, team, office and employment — and maps it to the right Entra ID groups and licences, which the native Simployer SCIM feed can’t do because it exposes Users only and no groups.
Absence is handled correctly: someone on long-term sick leave stays active in Entra ID, so a leave record is never mistaken for a leaver.
Nordic names — Norwegian and Swedish characters and patronymics — are transliterated into clean, unique UPNs instead of breaking sign-in.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | Simployer (Simployer One HRM) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | Simployer HR Connect API → Entra ID |
Supported events | Joiner, mover, leaver (incl. long-term absence, rehire, department transfer) |
Synced attributes | Name, email / UPN, department, team, job title, manager, office, cost center, start and end date |
Authentication | Bearer Access Token, created by an account Owner and scoped to the Simployer Public API |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync Simployer to Microsoft Entra ID?
Joinly reads each HR change from Simployer One through the HR Connect API and applies it to the matching Entra ID account automatically. Simployer holds the authoritative employee and employment record, so it is the starting point for each identity action.
Joiner. HR completes the hire in Simployer. Joinly reads the new employee and employment records and determines the role from attributes like department, team, office and cost center. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the employment start date.
Mover. When someone changes department, team or office in Simployer, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new position is revoked, so permissions stay aligned with the actual job — not with where the person started.
Leaver. On the employment end date recorded in Simployer, Joinly disables the Entra ID account automatically. There are no orphaned accounts left active after someone has left. A leave record — such as long-term sick leave — is treated as absence, not termination, so an employee on leave keeps their account.
Example: A Norwegian municipality hires a case worker in Simployer with a start date next Monday, in its Social Services department. Joinly reads the record, waits until the start date, creates the Entra ID account, assigns a Microsoft 365 licence and adds the case worker to the Social-Services group. When that person later goes on twelve weeks of parental leave, Joinly sees the leave record and leaves the account active and licensed, so nothing has to be recreated on their return.
What manual user management costs
Without automation, every account starts as a Simployer notification or a line in a spreadsheet that IT works through by hand. Simployer’s native SCIM Provisioning API can push a Users feed to services like Okta or Google Workspace, but it is one-way, exposes no groups and isn’t tested for Entra ID — so for a Microsoft shop the part that actually decides access still falls to people.
Onboarding delays. New joiners wait for accounts, licences and group access while a ticket sits in a queue, losing productive days in their first week.
Permissions that don’t keep up (privilege creep). When movers change department, team or office, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — and it is easy to disable someone who is only on long-term leave rather than actually gone.
Joinly vs. native Simployer / Entra provisioning
Simployer’s SCIM feed and Microsoft’s Entra API-driven inbound provisioning are a fine baseline, but they stop short of the part that actually decides access. Here’s how the two compare for a Simployer-driven Entra ID setup.
Joinly | Simployer SCIM / Entra inbound provisioning | |
|---|---|---|
Source | Reads the Simployer HR Connect API directly | Simployer SCIM Users feed; not tested for Entra |
Role-to-group mapping | Built in, rule-based on department, team and office | No groups in the SCIM feed; manual |
Absence vs leaver | Keeps accounts active during leave | No leave logic; risks disabling on absence |
Future-dated hires | Times account creation to the start date | Needs custom date-window configuration |
Licence assignment | Driven by role / attributes | Manual or group-based only |
On-premise AD | Yes, own agent plus the native Microsoft agent | Not covered by Simployer SCIM |
Audit trail | Per-action logging tied to the HR source | Limited |
Watch-outs when connecting Simployer to Microsoft Entra ID
A few Simployer-specific details decide whether this connection stays reliable at scale.
The native SCIM feed is source-only and has no groups. Simployer’s Provisioning API sends a Users feed out of Simployer and exposes no Groups endpoint, so it can’t drive role-to-group mapping or clean deprovisioning by itself. Joinly reads the richer HR Connect API instead and builds the group and licence logic from department, team and office.
Absence and long-term leave are not termination. Simployer treats sick leave and other absence as first-class records, and an employee on long-term leave is still active. A naive rule can read ‘absent’ as ‘gone’ and disable a live account. Joinly distinguishes a leave record from an employment end date, so access stays put during leave and is only removed when employment actually ends.
Nordic names and UPN format. Norwegian and Swedish names use characters like ae, o and a with diacritics, and patronymic surnames are common. A naive UPN rule produces broken or duplicate logins. Joinly applies transliteration and custom transformation rules — a suffix or controlled tiebreaker — so every UPN is clean, unique and predictable from day one.
Mapping Simployer structure to Entra groups. Organization, company, department, team, office and cost center don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from those structures to the correct groups and licences, so role drives access rather than manual assignment.
Mixed API generations. Some tenants still run the Simployer Classic HRConnect API alongside the newer Simployer One API. Joinly maps whichever object model your tenant exposes, so the connection doesn’t depend on which generation you are on.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which Simployer change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a Norwegian municipality with around 3,200 employees across schools, care homes and administrative offices, running Simployer as its HR core while its identity provisioning never quite keeps up. Simployer’s SCIM feed works for a couple of cloud tools, but it sends Users only with no groups, so every new case worker, teacher or care assistant still becomes a manual ticket in Entra ID — and with a steady stream of long-term sick leave and parental leave, accounts are sometimes disabled for people who are simply absent, then scrambled back to life when they return.
Connect Simployer to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change from the Simployer HR Connect API at the source and acts on it automatically: new hires have their account, Microsoft 365 licence and group access ready on their start date, transfers between departments swap the right groups the same day, employees on leave keep a stable, licensed account, and leavers are disabled on their employment end date with a 30-day soft-delete grace window.
“Long-term leave used to be the thing that tripped up every sync — we’d disable someone who was only on parental leave. Now an account is simply ready on the start date, leave leaves it untouched, and we can show the auditor exactly which Simployer change created every bit of access.” — Head of IT, Norwegian municipality
The outcome this setup is designed for: onboarding drops from days to zero touch, absence-related disable errors stop entirely, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone Simployer to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect Simployer to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the Simployer integration in the Joinly marketplace
Open the Joinly marketplace and search for the Simployer integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the Simployer integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your Simployer connection details: the HR Connect / Public API endpoint and the Access Token an account Owner generated in the Simployer Admin Center (scoped to the Public API). We only ask for the information needed to establish a successful connection with Simployer. All data is encrypted and stored securely.

Enter your Simployer API endpoint and Access Token in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from Simployer fields.
Frequently asked questions
How do I map the manager? Reference the manager on the Simployer employment record and Joinly resolves the link to the right manager automatically.
How do I handle absence? Map the leave record so an employee on long-term leave stays active; only an employment end date drives a leaver action.
How do I handle Nordic names? Use transliteration in the template and the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{lastName}”, “{initials}.{lastName}” }}

Map Simployer fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from Simployer should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in Simployer flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the employment end date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting Simployer to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the Simployer to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in Simployer reach Entra ID quickly without waiting for a nightly batch.
Why does Joinly use the HR Connect API instead of Simployer’s SCIM feed?
Simployer’s SCIM Provisioning API is one-way and exposes Users only, with no Groups endpoint, and it isn’t tested for Entra ID. Joinly reads the richer HR Connect / Public API so it can drive role-to-group mapping, licences and clean offboarding — not just a flat user list.
How does Joinly handle someone on long-term sick or parental leave?
A leave record in Simployer is treated as absence, not termination. Joinly keeps the account active and licensed during leave, and only disables it when the employment end date arrives, so nothing has to be recreated when the person returns.
Which attributes sync from Simployer to Entra ID?
Name, email / UPN, department, team, job title, manager, office, cost center, and start and end date. Custom Simployer fields can be mapped via Liquid templates.
Do I still need Simployer’s native SCIM feed or Entra’s inbound provisioning?
No. Joinly takes over the provisioning, role-to-group mapping and absence handling that the native paths do manually or not at all, and maintains it as your Simployer data changes.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the Simployer to Active Directory guide.


