From HR record to governed access, step by step.
This is the journey every identity takes through IDFusion — from your HR system to Microsoft Entra ID — and the journey your team takes to roll it out. Eight steps, each one automated, auditable and configured without code.
Point IDFusion at your HR systems.
Start where your people data already lives. Connect your HR sources through the connectors available in IDFusion — we are continually adding more, and can build a custom connector for your system. Data is imported securely in the background, on your schedule, with anything that needs attention gathered in one place.
- Pre-built HR connectors — A growing range of connectors for leading HR and payroll platforms, plus file import and custom connectors built for your system.
- Scheduled imports — Imports run in the background on the schedule you set.
- Primary + supplementary source — Enrich your primary HR source with one supplementary system — merged into a single identity.
- Import exceptions — Imports that need attention are gathered in one panel, so nothing fails quietly.
What this means for youYour HR system stays the one place people data is entered — and you know straight away when an import needs attention.
One identity, built from your two systems of record.
Designate a primary source per identity, then enrich it with a supplementary source — payroll, contracts, or a spreadsheet from the vendor manager. Each source’s own ID matches the records, and IDFusion merges the two into a single accurate record, with every field keeping its source.
Every change becomes a named event.
Most tools sync fields and leave you to guess what happened. IDFusion compares each incoming record with what it already knows and classifies the change as a lifecycle event — using rules you configure in the visual rule builder. Start from a ready-made set, adjust the conditions to match your policies, add events of your own and choose the order they are checked in. That signal drives everything downstream, including Entra Lifecycle Workflows.
- Configurable lifecycle rules — Define what each event means with the visual rule builder — no code.
- Ready-made starting set — New Hire, Late Hire, Reactivate, Offboarding, Late Termination and more — use them as they are or adapt them.
- Your own events, your order — Add events that match how your organisation works, switch them on or off, and set the order they are checked in.
- Event history — Every event recorded with the before and after state.
What this means for youEntra ID knows whether someone is a new hire, a returner or a leaver — so the right workflow runs, not a guess.
A ready-made starting set — change any rule, switch events on or off, or add your own.
Describe your organisation once. In rules, not scripts.
Business Roles are defined with a visual rule builder — office, department, job title, employment type — and evaluated automatically on every import. Priority ordering means the same person always gets the same roles.
- Visual rule builder — Point-and-click rules on any HR field.
- Priority-based evaluation — Same person, same roles, every time.
- Multiple automatic roles — Optionally match more than one Business Role per person.
- Rich condition types — Equals, contains and date comparisons, combined with AND / OR.
- Deactivate without deleting — Switch a Business Role off, and back on, without losing its rules or history.
What this means for youAccess decisions are written down once, in business terms, and applied the same way to everyone.
One platform, every kind of identity.
Personas classify each kind of identity — employee, contractor, vendor, clinician, student — and decide where each one provisions, below. Your Business Roles and lifecycle events stay global: one set of rules, applied consistently to every persona.
Many tenants and directories, one identity source of truth.
Employees into your corporate tenant. Contractors into corporate and the partner tenant. Clinicians into the subsidiary tenant and, for hybrid sites, on-premises Active Directory through Microsoft Entra — in the right organisational unit. Each target gets its own username rules and the attributes it needs, and multi-entity organisations give each person the sign-in domain of the entity they work for.
Each target is connected separately, with its own credentials. Pause provisioning per persona whenever you need to.
“Where will this person land?”
Before anything is created, preview a person’s persona, targets, username and Business Roles — so a new contractor or a rehire lands exactly where you expect.
- Many tenants and directories — Personas decide which Entra ID tenants and directories each person lands in.
- Attributes per target — Each target receives the attributes it needs.
- Username rules per target — Each tenant or directory can follow its own naming convention.
- Login domains per person — Multi-entity organisations give each person the sign-in domain of the entity they work for.
- Cloud and hybrid — Provision to on-premises Active Directory through Microsoft Entra, with each account placed in the right organisational unit.
- “Where will this person land?” — Preview a person’s persona, targets and Business Roles before anything is provisioned.
What this means for youEvery entity and directory you run is fed from the same HR record — no second process for the subsidiary.
Watch each identity travel to Entra ID.
This is the view your team lives in: every identity’s profile shows its journey from HR record to governed Entra ID account — each stage stamped, each target tracked. Usernames are previewed before they’re created, released for reuse when someone leaves, and rehires are handled cleanly.
What this means for youNew starters have a working account with the right details on day one, without a ticket to IT.
Build any Entra ID attribute — without code.
Compute the value an attribute needs with conditions, text and date logic, using the same kinds of functions your identity team already knows from Microsoft’s own provisioning. Every field can be mapped five ways: straight from HR, a fixed value, rule-based, from the lifecycle event, or an expression.
- Five ways to map a field — Straight from HR, a fixed value, rule-based, from the lifecycle event, or an expression.
- Conditions, text and date logic — If this, then that — join, trim, pad, change case and format dates.
- Familiar functions — Mirrors the functions identity teams already know from Microsoft’s own provisioning.
What this means for youThe attribute you need in Entra ID is configured by your own team — no script to write, no developer to wait for.
Access follows the role. Automatically, both ways.
IDFusion assigns each person’s Business Roles and keeps them on their Entra ID account. For every Business Role, IDFusion creates the matching Access Package in each target tenant, set up so Entra ID grants it automatically. Entra ID then grants the package while someone holds the role and removes it when they no longer do — using Microsoft’s own access governance. A role can be deactivated without being deleted.
- Business Roles kept in Entra ID — Each person’s Business Roles are kept current on their Entra ID account.
- Access Packages in every tenant — IDFusion creates the matching Access Package for each Business Role in every target tenant, set up so Entra ID grants it automatically.
- Granted and removed by Entra ID — Entra ID grants the package while someone holds the role, and removes it when they no longer do.
- No manual step — One change in HR flows through to access.
What this means for youPeople get what their role needs and lose what it doesn’t — decided inside Microsoft’s own governance controls, with nobody keeping a spreadsheet.
Run it with evidence, not faith.
Every classification, rule match and provisioning step lands in the audit trail with the actor, the input and the outcome. Watch events flow through the portal, see anything that needs attention, and give auditors and reviewers their own view.
- Full audit trail — Every action, who took it and when.
- Import log — History for every HR connection.
- Lifecycle event history — Every classification with its before and after state.
- Auditor view — A dedicated view for auditors and compliance reviewers.
- Notifications — Tell your service desk or another system when an account is ready.
- Portal roles — Portal access controlled by roles you assign — administrators for your identity team, an auditor view for reviewers.
- Provisioning queue — See what is waiting, in progress and done.
- Monitored by our team — The platform is monitored by the IDFusion team.
What this means for youWhen the auditor asks who had access and why, the answer is already written down.
See the whole workforce — then any one person.
Dashboards show how much of your workforce is provisioned into each target, how identities split across personas, and joiners and leavers over the last 30 days. The Identity profile shows every account a person has across every target, their provisioning timeline, and recent activity and failures — with concurrent jobs shown clearly.
What this means for youLeaders see coverage and churn at a glance; your service desk sees one person’s full story in one place.
Work at workforce scale. Stay in control.
Search, sort and filter across large workforces — by HR source or any HR field — and provision a whole filtered list at once, with a confirmation step and safe batch limits. When you need to slow down, pause a persona, park an individual, or switch automatic provisioning off.
- Fast search, sort and filter — Find anyone across a large workforce.
- Filter by source or any HR field — Narrow the list by HR source, department, location or any other field.
- Lists for every population — Employees, contractors, students — each population in its own list.
- Bulk provisioning — Provision a filtered list in one go, with a confirmation step and safe batch limits.
- Pause per persona — Pause provisioning for one persona while the others carry on.
- Park and unpark — Parked people are held back from provisioning until you unpark them.
- Automatic provisioning on or off — Switch automatic provisioning on when you’re ready to go live.
- One or several automatic personas — A person can match one automatic persona, or several.
What this means for youYour team acts on a whole population at once, safely, instead of one record at a time. Your team decides the pace — hold a population, or one person, until you are ready.
Security & assurance, built in.
Each customer’s data is kept separate, credentials are locked away, your team signs in with your own Entra ID, and every action leaves audit evidence. Failed steps are retried automatically, and provisioning paces itself during heavy periods. The full security story has its own page.
Frequently asked questions.
Don’t see your question? Ask us — we’re happy to walk your team through it.
Instead of deploying a fully-featured third-party IGA platform, IDFusion acts as an integration shim that complements the Entra ecosystem by only providing the additional enterprise integration features required, rather than creating overlapping IGA capabilities natively included in the Entra ecosystem.
IDFusion’s approach preserves native Entra IGA features, ensuring the full benefits of the Microsoft Entra integrated ecosystem are retained. The result is much lower integration complexity by retaining core access, authentication, authorisation and identity governance controls within the Entra ecosystem.
See this journey, step by step.
The fastest way to evaluate IDFusion is a live walkthrough: each step shown in IDFusion, and how it flows through to Microsoft Entra ID.