When someone joins, moves or leaves in TriNet, you want that change reflected in Microsoft Entra ID without anyone touching it by hand. To connect TriNet to Microsoft Entra ID, Joinly reads each HR change from your TriNet tenant at the source and applies it automatically to the right account. TriNet stays your source of truth; Joinly is the engine that keeps every action accurate and traceable — including the co-employment details that trip up generic sync tools.
Key takeaways
TriNet stays your source of truth; Joinly applies every joiner, mover and leaver to Entra ID automatically.
Joinly reads the right TriNet product for your setup — the TriNet PEO Platform or the TriNet HR Platform (formerly Zenefits) — so it connects to where your employee data actually lives.
Joinly keys on employment status, not record presence, so a terminated worksite employee whose record is deactivated (but never deleted) is offboarded correctly rather than left looking active.
Worksite employees are mapped to the right Entra ID groups and licences by role, while non-WSE or contractor records can be filtered out — something a raw API feed leaves to you.
Every action is logged for a complete audit trail, aligned with NIS2 and ISO 27001.
Quick facts
Source system | TriNet (PEO Platform or HR Platform, formerly Zenefits) |
Target system | Microsoft Entra ID (formerly Azure AD) |
Connection method | TriNet authenticated HR feed → Joinly → Entra ID |
Supported events | Joiner, mover, leaver (incl. rehire and status changes) |
Synced attributes | Name, email / UPN, department, job title, manager, location, employment type, start and end date |
Authentication | Approved, keyed TriNet access; SSO via SAML supported |
Real-time or batch | Frequent sync, multiple times per day |
Compliance | ISO 27001, NIS2-ready, GDPR (EU data centre) |
How does Joinly sync TriNet to Microsoft Entra ID?
Joinly reads each HR change from your TriNet tenant and applies it to the matching Entra ID account automatically. TriNet holds the authoritative employment record, so it is the starting point for each identity action — and Joinly reads the correct TriNet product for your setup, whether that is the PEO Platform or the HR Platform.
Joiner. HR completes the hire in TriNet. Joinly reads the new worksite-employee record and determines the role from attributes like department, job title and location. It then creates the account in Entra ID, assigns the right licences and maps the person into the correct groups — timed to the start date.
Mover. When someone changes department, location or manager in TriNet, Joinly updates their group membership, permissions and licences to match. Access that no longer fits the new role is revoked, so permissions stay aligned with the actual job.
Leaver. On the termination recorded in TriNet, Joinly disables the Entra ID account automatically. Because TriNet deactivates a terminated record rather than deleting it, Joinly reads the employment status — not the mere presence of the record — so leavers are offboarded on time and no orphaned accounts stay active.
Example: A professional-services firm hires a consultant in TriNet with a start date next Monday. Joinly reads the new worksite-employee record, waits until the start date, creates the Entra ID account, assigns an Office E3 licence and adds the consultant to the Consulting-EU group. When the consultant later moves from delivery to the strategy practice, Joinly swaps the group membership the same day, and when they leave, the deactivated TriNet status triggers a clean offboarding instead of leaving the account live.
What manual user management costs
Without automation, every account starts as a request from TriNet or a line in a spreadsheet that IT works through by hand. A raw TriNet API feed or a generic iPaaS flow can move attributes across, but it leaves role-to-group mapping, worksite-employee filtering and co-employment status handling to you — so the part that actually decides access still falls to people.
Onboarding delays. New joiners wait for accounts, licences and group access while a request sits in a queue, losing productive days in their first week.
Permissions that don’t keep up (privilege creep). When movers change department or location, old access often stays attached, so people accumulate rights they no longer need.
Forgotten offboarding. Accounts that aren’t disabled on time are both a security and audit risk, and unused licences keep costing money — and because TriNet only deactivates terminated records rather than deleting them, a status-blind script can miss the leaver entirely.
Joinly vs. a raw TriNet API integration
There is no first-party Entra inbound provisioning app for TriNet, so the usual alternative is a custom integration against the TriNet API or a unified-HRIS broker. That moves data, but it stops short of the part that actually decides access. Here’s how the two compare.
Joinly | Raw TriNet API / iPaaS broker | |
|---|---|---|
Source | Reads the right TriNet product (PEO or HR Platform) | You build against whichever TriNet endpoint you can key into |
Role-to-group mapping | Built in, rule-based on department, title and location | Not provided; you write the logic yourself |
Worksite-employee filtering | Filters WSE vs non-WSE / contractor by status and type | Raw feed includes everyone; you filter manually |
Terminated-record handling | Keys on employment status, not record presence | Easy to treat a deactivated record as still active |
Licence assignment | Driven by role / attributes | Manual or group-based only |
On-premise AD | Yes, own agent plus the native Microsoft agent | Separate build required |
Audit trail | Per-action logging tied to the HR source | Whatever you build and maintain |
Watch-outs when connecting TriNet to Microsoft Entra ID
A few TriNet-specific details decide whether this connection stays reliable at scale.
Co-employment record retention. Because TriNet is a co-employer, a terminated worksite employee’s record is deactivated for compliance, not deleted. A rule that checks whether a record exists will treat a leaver as active. Joinly keys on employment status, so offboarding fires on the actual termination.
Two TriNet products, two data shapes. The TriNet PEO Platform and the TriNet HR Platform (formerly Zenefits) expose employees differently. Joinly connects to the product your tenant actually uses, so the feed matches your real setup instead of guessing.
Worksite employees vs the rest. Not every TriNet record should get an Entra ID account — contractors and non-WSE entries often shouldn’t. Joinly filters by employment type and status, so only the people who need an account get one.
Role-to-group mapping. TriNet’s department, job title and location don’t translate one-to-one to Entra ID groups. Joinly builds explicit mapping rules from those attributes to the correct groups and licences, so role drives access rather than manual assignment.
UPN format with duplicate names. When two employees share a name, a naive UPN rule produces collisions. Joinly applies custom transformation rules — a suffix, location code or controlled tiebreaker — so every UPN is unique and predictable from day one.
Joinly handles each of these by default with custom mapping and transformation.
Always audit-ready
Every account action Joinly performs is logged: who was affected, when it happened, which access changed and which TriNet change triggered it. For NIS2 that matters directly: access can be traced back to an authorised HR source rather than an ad-hoc request. Joinly is ISO 27001 certified, runs in an EU data centre in Amsterdam, applies least-privilege by default, and is built to meet NIS2 and ISO 27001.
Example case
Picture a professional-services firm with around 900 consultants across four European offices, running TriNet for its US-linked entity and HR administration while its identity provisioning never quite keeps up. IT builds accounts by hand from a weekly TriNet export, and the mismatches pile up: contractors slip into the same feed as worksite employees and get accounts they shouldn’t, and when a consultant leaves, the deactivated TriNet record still looks present to the old script, so the account lingers for weeks.
Connect TriNet to Microsoft Entra ID with Joinly and that work disappears. Joinly reads each HR change from TriNet at the source and acts on it automatically: new consultants have their account, Office licence and group access ready on their start date, moves between practices swap the right groups the same day, only real worksite employees are provisioned, and leavers are disabled the moment their TriNet status flips to terminated — with a 30-day soft-delete grace window.
“Terminated people used to linger because our script only checked whether the record was still there. Now Joinly reads the actual status, the account is disabled on the leave date, and I can show the auditor exactly which TriNet change created every bit of access.” — Head of IT, professional-services firm
The outcome this setup is designed for: onboarding drops from days to zero touch, terminated-record errors stop entirely, and the team can walk into its next NIS2 assessment with a complete, source-backed audit trail.
More than a connector
A standalone TriNet to Entra ID connection is a good start, but identity rarely stops at one target. Joinly manages the complete chain from joiner to leaver across all your systems, with logging and governance built in. You review the exceptions; Joinly maintains the chain.
Schedule a demo
Installation guide
Follow these steps to connect TriNet to Microsoft Entra ID with Joinly. The entire cloud setup happens in the platform, with no scripts or local software required.
1. Create your account
Go to platform.joinly.app and create your account.
Note: charges may apply for using the platform after the trial period ends.

Sign up at platform.joinly.app to get started.
2. Connect your Microsoft account
Open platform.joinly.app/settings/provisioning/idp-setup and connect your Microsoft tenant. Select the scopes you need. For provisioning you don’t need any additional scopes.

Connect your Microsoft tenant and pick your scopes.
3. Import your existing accounts from Entra ID
Import all existing accounts from Entra ID at platform.joinly.app/settings/provisioning/entra-import. This gives Joinly a baseline of every account that already exists, so it can match people to their current account instead of creating duplicates.
4. Find the TriNet integration in the Joinly marketplace
Open the Joinly marketplace and search for the TriNet integration.
Don’t see your system listed? Get in touch at support@koppelhet.nl and we’ll help you out.

Search the marketplace for the TriNet integration.
5. Follow the installation wizard
You may be redirected to integrations.joinly.app. Create an account there and enter your TriNet connection details: which TriNet product you use (PEO Platform or HR Platform) and the API credentials issued to you by TriNet. We only ask for the information needed to establish a successful connection with TriNet. All data is encrypted and stored securely.

Enter your TriNet product and API credentials in the wizard.
6. Configure your field mapping
Set up all your field mappings here. Templates support Liquid, so you can build your display name, UPN and other attributes dynamically from TriNet fields.
Frequently asked questions
How do I map the manager? Reference the manager identifier in the mapping and Joinly resolves the link to the right manager automatically.
How do I exclude contractors? Filter on employment type and status so only worksite employees are provisioned.
How do I prevent duplicate usernames? Use the
generateUniqueUsernamehelper, which falls back to the next pattern when the first one is already taken:{{ generateUniqueUsername: “{firstName}.{prefix}.{lastName}”, “{initials}.{prefix}.{lastName}” }}

Map TriNet fields to Entra ID attributes with Liquid templates.
7. Configure the scheduled import
At platform.joinly.app/settings/import-configs, configure how often the import from TriNet should run.
8. Configure your workflows
Workflows are where Joinly turns each HR change into the right action in Entra ID. Create an onboarding (joiner) and offboarding (leaver) workflow with trigger-based execution, then an Identity updated workflow with a Create/update employee in Entra action so every change in TriNet flows straight through to Entra ID. Finally, add a threshold workflow with the Entra soft delete action that runs a set period after the termination date (for example 30 days) to retire accounts safely.

Create a trigger-based onboarding workflow.

Add the create/update action, then set your matching strategy and field mapping.

Add the Entra soft delete action to retire accounts safely.
## AD on-premise support
Need to provision to an on-premise Active Directory as well? See our dedicated guide on connecting TriNet to Active Directory, or contact support at support@koppelhet.nl to request setup of the Joinly AD Agent.
Frequently asked questions
Does the TriNet to Microsoft Entra ID connection work in real time?
It runs as a frequent sync that updates multiple times per day, so changes in TriNet reach Entra ID quickly without waiting for a nightly batch.
Does TriNet have a SCIM API for provisioning?
TriNet does not publish a documented SCIM 2.0 user-management API. Joinly connects through the authenticated TriNet feed available to your tenant and handles the provisioning, mapping and status logic itself, so you don’t depend on a native SCIM endpoint.
How does Joinly handle terminated employees when TriNet only deactivates the record?
Joinly keys on the employment status rather than whether the record still exists, so a deactivated (but not deleted) worksite-employee record is correctly recognised as a leaver and the Entra ID account is disabled on time.
Which attributes sync from TriNet to Entra ID?
Name, email / UPN, department, job title, manager, location, employment type, and start and end date. Additional fields can be mapped via Liquid templates.
Can Joinly connect both TriNet products?
Yes. Joinly connects to the TriNet PEO Platform or the TriNet HR Platform (formerly Zenefits) — you tell it which one your tenant uses so the feed matches your setup.
Does Joinly also support AD on-premise or hybrid provisioning?
Yes. Joinly has its own AD on-premise agent and also supports the native Microsoft Entra provisioning agent, so you can provision users to your on-premise AD environment as well. See the TriNet to Active Directory guide.


