NewBuild any Microsoft Entra ID attribute without code — conditions, text and date logic, no scripts. See how →
Identity Journey

From HR record to governed access, step by step.

This is the journey every identity takes through IDFusion — from your HR system to Microsoft Entra ID — and the journey your team takes to roll it out. Eight steps, each one automated, auditable and configured without code.

Step 01 · Connect

Point IDFusion at your HR systems.

Start where your people data already lives. Connect your HR sources through the connectors available in IDFusion — we are continually adding more, and can build a custom connector for your system. Data is imported securely in the background, on your schedule, with anything that needs attention gathered in one place.

  • Pre-built HR connectors — A growing range of connectors for leading HR and payroll platforms, plus file import and custom connectors built for your system.
  • Scheduled imports — Imports run in the background on the schedule you set.
  • Primary + supplementary source — Enrich your primary HR source with one supplementary system — merged into a single identity.
  • Import exceptions — Imports that need attention are gathered in one panel, so nothing fails quietly.

What this means for youYour HR system stays the one place people data is entered — and you know straight away when an import needs attention.

YOUR HR SOURCES → IDFUSION
HR system Payroll Contractor source File import Custom IDFusion SECURE IMPORT
EXAMPLE · IMPORT STATUS
Dayforce Scheduled · 6:00 am Completed
Payroll system Scheduled · 6:30 am 2 need attention
Contractors.csv Scheduled · 7:00 am Completed

One identity, built from your two systems of record.

Designate a primary source per identity, then enrich it with a supplementary source — payroll, contracts, or a spreadsheet from the vendor manager. Each source’s own ID matches the records, and IDFusion merges the two into a single accurate record, with every field keeping its source.

Step 02 · Classify

Every change becomes a named event.

Most tools sync fields and leave you to guess what happened. IDFusion compares each incoming record with what it already knows and classifies the change as a lifecycle event — using rules you configure in the visual rule builder. Start from a ready-made set, adjust the conditions to match your policies, add events of your own and choose the order they are checked in. That signal drives everything downstream, including Entra Lifecycle Workflows.

If end date is set · and in the future Offboarding
If end date is cleared · and the person already exists in IDFusion Reactivate
If new starter · start date already passed Late Hire
  • Configurable lifecycle rules — Define what each event means with the visual rule builder — no code.
  • Ready-made starting set — New Hire, Late Hire, Reactivate, Offboarding, Late Termination and more — use them as they are or adapt them.
  • Your own events, your order — Add events that match how your organisation works, switch them on or off, and set the order they are checked in.
  • Event history — Every event recorded with the before and after state.

What this means for youEntra ID knows whether someone is a new hire, a returner or a leaver — so the right workflow runs, not a guess.

EXAMPLE · YOUR LIFECYCLE RULES, IN YOUR ORDER
New Hire New starter added on time
Late Hire New starter added after their start date (threshold you set)
Initial Load First-time bulk sync for a data source
Reactivate Returning employee — end date removed
Offboarding Termination effective in the future
Late Termination Termination already past its effective date
Workforce Transition Role / department change, no termination
Data Correction Start-date change on a provisioned employee
Update Routine attribute update (none of the above)
+ Your own event Conditions you define in the rule builder

A ready-made starting set — change any rule, switch events on or off, or add your own.

Step 03 · Model

Describe your organisation once. In rules, not scripts.

Business Roles are defined with a visual rule builder — office, department, job title, employment type — and evaluated automatically on every import. Priority ordering means the same person always gets the same roles.

  • Visual rule builder — Point-and-click rules on any HR field.
  • Priority-based evaluation — Same person, same roles, every time.
  • Multiple automatic roles — Optionally match more than one Business Role per person.
  • Rich condition types — Equals, contains and date comparisons, combined with AND / OR.
  • Deactivate without deleting — Switch a Business Role off, and back on, without losing its rules or history.

What this means for youAccess decisions are written down once, in business terms, and applied the same way to everyone.

One platform, every kind of identity.

Personas classify each kind of identity — employee, contractor, vendor, clinician, student — and decide where each one provisions, below. Your Business Roles and lifecycle events stay global: one set of rules, applied consistently to every persona.

RULE BUILDERExample data · live preview
When an employee matches ALL of:
Then assign:
The role carries its Access Packages — Entra ID grants them automatically while someone holds it.
247 example employees match this ruleauto-evaluated on import

Many tenants and directories, one identity source of truth.

Employees into your corporate tenant. Contractors into corporate and the partner tenant. Clinicians into the subsidiary tenant and, for hybrid sites, on-premises Active Directory through Microsoft Entra — in the right organisational unit. Each target gets its own username rules and the attributes it needs, and multi-entity organisations give each person the sign-in domain of the entity they work for.

EXAMPLE · PERSONAS → WHERE THEY PROVISION
Employee Full lifecycle from HR
Corporate
Contractor Engagement-length driven
CorporatePartner
Vendor Minimal footprint
Partner
Clinician Credential-aware access
CorporateSubsidiaryOn-prem AD
TARGETS
Corporate tenant acme.com
Partner tenant partners.acme.com
Subsidiary tenant clinics.acme.health
On-premises Active Directory through Microsoft Entra · Clinical staff unit

Each target is connected separately, with its own credentials. Pause provisioning per persona whenever you need to.

“Where will this person land?”

Before anything is created, preview a person’s persona, targets, username and Business Roles — so a new contractor or a rehire lands exactly where you expect.

  • Many tenants and directories — Personas decide which Entra ID tenants and directories each person lands in.
  • Attributes per target — Each target receives the attributes it needs.
  • Username rules per target — Each tenant or directory can follow its own naming convention.
  • Login domains per person — Multi-entity organisations give each person the sign-in domain of the entity they work for.
  • Cloud and hybrid — Provision to on-premises Active Directory through Microsoft Entra, with each account placed in the right organisational unit.
  • “Where will this person land?” — Preview a person’s persona, targets and Business Roles before anything is provisioned.

What this means for youEvery entity and directory you run is fed from the same HR record — no second process for the subsidiary.

EXAMPLE · PLACEMENT PREVIEW · TOM WALSH
Persona Contractor Employment type = Contractor
Targets Corporate tenant · Partner tenant 2 accounts
Username tom.walsh@acme.com Preview from your username rule
Business Roles Project Delivery Rule matched
Nothing is provisioned until you are ready.
Step 04 · Provision

Watch each identity travel to Entra ID.

This is the view your team lives in: every identity’s profile shows its journey from HR record to governed Entra ID account — each stage stamped, each target tracked. Usernames are previewed before they’re created, released for reuse when someone leaves, and rehires are handled cleanly.

Sarah Chen EXAMPLE · EMP-4421 · Engineering · Sydney
New Hire Senior Engineer
Imported Dayforce
Classified New Hire
Role assigned Senior Engineer
Provisioned Entra ID
Attributes synced Protected + standard
Access granted by Entra ID 2 packages
TargetDetailStatus
Microsoft Entra ID Account created automatically Provisioned
Username sarah.chen@acme.com Created
Protected attributes Clearance level · Cost centre Synced
Access Packages Azure DevOps · Engineering Tools · granted by Entra ID Granted
Notification Service desk told the account is ready Sent
Automated account creation — Accounts created and kept up to date as people join, move and leave.
Username rules with preview — Define rules once and preview the username for any person before the account exists.
Username release and rehires — Usernames are released for reuse when someone leaves, and returning staff are handled cleanly.
Standard attribute sync — Department, job title, manager and more.
Multi-valued attributes — Addresses and other multi-valued details kept in sync.
Protected attributes — Sensitive fields held as Custom Security Attributes only authorised admins can see.
Automatic retries — Failed steps are retried automatically, so a temporary hiccup doesn’t become a ticket.
Paces itself under load — During heavy periods provisioning slows its pace rather than failing.
Status tracking — Follow each account through to completion.

What this means for youNew starters have a working account with the right details on day one, without a ticket to IT.

No-code attribute builder

Build any Entra ID attribute — without code.

Compute the value an attribute needs with conditions, text and date logic, using the same kinds of functions your identity team already knows from Microsoft’s own provisioning. Every field can be mapped five ways: straight from HR, a fixed value, rule-based, from the lifecycle event, or an expression.

  • Five ways to map a field — Straight from HR, a fixed value, rule-based, from the lifecycle event, or an expression.
  • Conditions, text and date logic — If this, then that — join, trim, pad, change case and format dates.
  • Familiar functions — Mirrors the functions identity teams already know from Microsoft’s own provisioning.

What this means for youThe attribute you need in Entra ID is configured by your own team — no script to write, no developer to wait for.

Build value expressionDisplay nameExample · Expression builder
ConditionExpressionPost-apply· first matching branch wins
IFwherePreferred Nameis not empty✓ MATCHEDPreferred Name = “tom” → is not empty ✓
Then the value isConcatenate parts
Preferred NameProper case= Tom␣= ␣SurnameProper case= Walsh+ Field+ Text
OTHERWISEno branch matched — use this expressionskipped — the IF branch matched
Then the value isConcatenate parts
Given NameProper case= Thomas␣= ␣SurnameProper case= Walsh+ Field+ Text
+ Add condition branch
Post-apply— transforms applied to whichever branch winsTrim“Tom Walsh” → “Tom Walsh”
Live Previewagainst sample values
Tom Walsh
→ IF branch matched
Preferred Name + ␣ + Surname · Proper case · Trim
9 chars
Sample valuesedit to test branches
Map any field five waysFrom HRFixed valueRule-basedLifecycle eventExpression
Step 05 · Grant access

Access follows the role. Automatically, both ways.

IDFusion assigns each person’s Business Roles and keeps them on their Entra ID account. For every Business Role, IDFusion creates the matching Access Package in each target tenant, set up so Entra ID grants it automatically. Entra ID then grants the package while someone holds the role and removes it when they no longer do — using Microsoft’s own access governance. A role can be deactivated without being deleted.

  • Business Roles kept in Entra ID — Each person’s Business Roles are kept current on their Entra ID account.
  • Access Packages in every tenant — IDFusion creates the matching Access Package for each Business Role in every target tenant, set up so Entra ID grants it automatically.
  • Granted and removed by Entra ID — Entra ID grants the package while someone holds the role, and removes it when they no longer do.
  • No manual step — One change in HR flows through to access.

What this means for youPeople get what their role needs and lose what it doesn’t — decided inside Microsoft’s own governance controls, with nobody keeping a spreadsheet.

EXAMPLE · BUSINESS ROLE → ENTRA ID GRANTS ACCESS
Senior EngineerBusiness Role matched
synced to Entra ID · Entra ID grants
Azure DevOps Access Package
Engineering Tools Access Package
VPN Access Access Package
Role removed? Entra ID removes the same packages — automatically.
Step 06 · Operate

Run it with evidence, not faith.

Every classification, rule match and provisioning step lands in the audit trail with the actor, the input and the outcome. Watch events flow through the portal, see anything that needs attention, and give auditors and reviewers their own view.

  • Full audit trail — Every action, who took it and when.
  • Import log — History for every HR connection.
  • Lifecycle event history — Every classification with its before and after state.
  • Auditor view — A dedicated view for auditors and compliance reviewers.
  • Notifications — Tell your service desk or another system when an account is ready.
  • Portal roles — Portal access controlled by roles you assign — administrators for your identity team, an auditor view for reviewers.
  • Provisioning queue — See what is waiting, in progress and done.
  • Monitored by our team — The platform is monitored by the IDFusion team.

What this means for youWhen the auditor asks who had access and why, the answer is already written down.

EXAMPLE EVENT STREAMIllustrative data
New HireSarah Chen · Senior Engineer · Engineering · Sydney
ReactivateMarcus Webb · Sales Director · Sales · Melbourne
OffboardingPriya Nair · Clinical Lead · Operations · Auckland
Workforce TransitionTom Weatherall · Analyst · Finance · Singapore
UpdateAiko Tanaka · Office Manager · Clinical · London
Late HireJames Okafor · Contractor · Marketing · Sydney
Step 07 · Oversee

See the whole workforce — then any one person.

Dashboards show how much of your workforce is provisioned into each target, how identities split across personas, and joiners and leavers over the last 30 days. The Identity profile shows every account a person has across every target, their provisioning timeline, and recent activity and failures — with concurrent jobs shown clearly.

WORKFORCE DASHBOARDExample data
Provisioning coverage
Corporate tenant98%
Partner tenant93%
On-premises AD96%
Identities by persona
  • Employee70%
  • Contractor16%
  • Vendor4%
  • Clinician10%
Joiners & leavers · last 30 days64 joiners41 leavers
Priya NairIDENTITY PROFILE · 2 concurrent jobsExample data
Registered NursePrimaryWestmead Clinic
Clinical EducatorConcurrentParramatta Campus
Accounts in every target
Corporate tenantpriya.nair@acme.healthProvisioned
Clinics tenantp.nair@clinics.acme.healthProvisioned
On-premises ADUnit: Clinical staffProvisioned
Recent activity
Today 9:12 amJob title updated from HRSynced
Today 9:14 amBusiness Role synced to Entra ID: Clinical staffSynced
YesterdayAttribute update did not completeRetried · done
2 days agoWorkforce Transition classifiedDone
Provisioning coverage — How much of your workforce is provisioned into each target.
Identity distribution — How your people split across personas.
Joiners and leavers — Joiners and leavers over the last 30 days.
Identity profile — Every person’s accounts across every target, in one view.
Provisioning timeline — Each step for each person, stamped as it happens.
Recent activity and failures — What changed for a person, and anything that needs attention.
Concurrent jobs — People who hold more than one job are shown clearly.

What this means for youLeaders see coverage and churn at a glance; your service desk sees one person’s full story in one place.

Step 08 · Scale & control

Work at workforce scale. Stay in control.

Search, sort and filter across large workforces — by HR source or any HR field — and provision a whole filtered list at once, with a confirmation step and safe batch limits. When you need to slow down, pause a persona, park an individual, or switch automatic provisioning off.

  • Fast search, sort and filter — Find anyone across a large workforce.
  • Filter by source or any HR field — Narrow the list by HR source, department, location or any other field.
  • Lists for every population — Employees, contractors, students — each population in its own list.
  • Bulk provisioning — Provision a filtered list in one go, with a confirmation step and safe batch limits.
  • Pause per persona — Pause provisioning for one persona while the others carry on.
  • Park and unpark — Parked people are held back from provisioning until you unpark them.
  • Automatic provisioning on or off — Switch automatic provisioning on when you’re ready to go live.
  • One or several automatic personas — A person can match one automatic persona, or several.

What this means for youYour team acts on a whole population at once, safely, instead of one record at a time. Your team decides the pace — hold a population, or one person, until you are ready.

EXAMPLE · BULK PROVISIONING
Source: DayforceDepartment: ClinicalNot yet provisioned
86 people match these filters Provisioned in safe batches after you confirm.
EXAMPLE · CONTROLS
Automatic provisioning On
Contractor persona Paused
Parked people 3 held back
Underneath it all

Security & assurance, built in.

Each customer’s data is kept separate, credentials are locked away, your team signs in with your own Entra ID, and every action leaves audit evidence. Failed steps are retried automatically, and provisioning paces itself during heavy periods. The full security story has its own page.

Security & compliance
Questions

Frequently asked questions.

Don’t see your question? Ask us — we’re happy to walk your team through it.

Instead of deploying a fully-featured third-party IGA platform, IDFusion acts as an integration shim that complements the Entra ecosystem by only providing the additional enterprise integration features required, rather than creating overlapping IGA capabilities natively included in the Entra ecosystem.

IDFusion’s approach preserves native Entra IGA features, ensuring the full benefits of the Microsoft Entra integrated ecosystem are retained. The result is much lower integration complexity by retaining core access, authentication, authorisation and identity governance controls within the Entra ecosystem.

See it live

See this journey, step by step.

The fastest way to evaluate IDFusion is a live walkthrough: each step shown in IDFusion, and how it flows through to Microsoft Entra ID.