Connect trusted workforce data from Bob and reduce manual work with IT-controlled account provisioning in on-premises Active Directory via Microsoft Entra ID— helping HR and IT stay in sync across the employee lifecycle.
By Ido Stern, senior vice president, Platform Engineering, HiBob
Every employee change starts in HR, but its consequences extend into IT. When someone joins, changes roles, moves teams, or leaves, the employee record changes first. HR and IT each own a critical part of what happens next: HR keeps workforce information accurate and current, while IT makes sure the corresponding identity and account changes happen under the right control.
When those processes fall out of sync, the gap between the employee record and account state can delay account setup, leave identity data outdated, contribute to access drift, and keep accounts active longer than intended.
From a platform engineering perspective, this is where connected systems prove their value. The goal isn’t to move ownership away from IT. It’s to connect HR and IT responsibilities more reliably, so that HR maintains the trusted workforce data, while IT governs how those changes are applied across systems it already trusts.
Key takeaways: HiBob’s Microsoft Active Directory (Hybrid) integration
- Manual HR-to-IT handoffs can cause workforce changes to fall out of sync with account status. Delays and duplicate updates can affect onboarding, role and team changes, and offboarding.
- IT controls how workforce changes are handled in the Microsoft environment. IT defines mappings, scope, provisioning rules, approvals, and exceptions while reducing the need to process every routine update manually.
- Bob, Microsoft Entra ID, and on-premises Active Directory each have a distinct role. Bob provides the workforce change signal, Microsoft Entra ID applies IT-configured rules, and Active Directory receives the account action.
- HiBob’s Microsoft Active Directory (Hybrid) integration can reduce the long-term burden of custom development. IT can avoid owning another custom dependency to test, maintain, update, troubleshoot, and support as systems change.
Where manual HR-to-IT handoffs create risk
HR and IT own different parts of the same workforce event. HR maintains the employee record; IT is accountable for whether the corresponding account is ready, current, and deactivated on time.
In hybrid Microsoft environments, a change may cross systems, teams, and approvals. Forms, tickets, scripts, and duplicate entries can bridge the steps, but each handoff creates another opportunity for information to be delayed, duplicated, or fall out of sync. The question is whether the latest workforce change leads to the appropriate account action under rules IT can govern and review.
How HiBob connects workforce changes to IT-controlled provisioning
HiBob’s Microsoft Active Directory (Hybrid) integration follows a clear flow: Bob → Microsoft Entra ID → on-premises Active Directory.
Bob holds trusted employee data and records joins, internal moves, departures, and inactive team members. It sends relevant information to Microsoft Entra ID, which applies the mappings, scope, provisioning rules, and approval requirements configured by IT. Through Microsoft’s provisioning setup, the account in on-premises Active Directory can be created, updated, or deactivated.
Provisioning means creating and maintaining a team member’s work account based on changes in the employment record.
For a new hire, the flow can support timely account creation. Mapped changes to role, manager, department, location, or employment status can keep identity information aligned. When someone leaves or becomes inactive, the integration can support account deactivation according to the organization’s configuration.
The boundaries matter: Bob provides the signal, Microsoft Entra ID applies IT’s configured process, and on-premises Active Directory is the target. The integration does not replace Microsoft’s identity systems, the organization’s identity and access management strategy, or IT’s ownership of access.
How IT keeps control of provisioning
The integration is driven by trusted HR data and governed by IT. HR records the employment change in Bob; Bob provides the signal; IT determines how it is handled in the Microsoft environment.
Instead of re-entering every routine change, IT defines the governance model. Teams choose the data, employee scope, field mappings, and provisioning rules. They can require approval for new accounts or review of changes to department, manager, or job title, and decide who receives the approval notification.
Automation doesn’t mean giving up control. It means baking IT’s rules into the process itself. Routine changes can proceed automatically where permitted, while selected, sensitive changes remain subject to human review. IT still decides what can happen automatically, what requires approval, and where exceptions need direct oversight.
Recommended For Further Reading
How a supported integration reduces long-term IT burden
A supported integration matters because the cost and complexity of a custom build do not end when the connector works. Bespoke functionality still needs testing, maintenance, updates, troubleshooting, and support as systems and requirements change.
The real architectural decision is not only whether a team can build the connection. It is whether the organization wants to own and maintain another custom dependency over time.
Good platform engineering should strengthen the environment a customer already trusts. We designed this integration to work with Microsoft Entra ID and on-premises Active Directory, not to ask IT teams to replace them. A supported integration can reduce repeated handoffs and manual account updates while preserving the customer’s identity architecture and governance model.
During beta testing, Novuna explained why a supported path can be more sustainable than bespoke development:
“Before the opportunity to participate in the beta programme, we were exploring custom development to achieve similar functionality. While that approach may have met the requirement, it would have introduced additional complexity, ongoing maintenance, and support overhead. Having a supported integration available is a much more sustainable solution for us.”
— Chris, Automation Lead | Alex, HR Systems Consultant
Novuna
For Novuna, the value of a supported integration is clear: It offers a more sustainable path than adding another custom dependency for IT to build, maintain, and support over time.
Turning trusted workforce data into governed action
This integration is one proof point for Bob’s broader value to IT: Bob helps connect trusted employee data to the systems and processes where IT can govern and act on it. Employee data becomes operational when a change in HR can reliably inform a controlled action across the business—not when it simply sits in a record.
HR remains responsible for the accuracy and timing of the employee record. IT remains responsible for account governance, access decisions, and the identity environment. The integration connects those responsibilities more reliably without blurring who owns what.
For us, that is the platform opportunity: clear system boundaries, trusted data made useful where work happens across the business, and support for the controls customers already rely on. The strongest HR and IT partnerships depend on that coordination: clear ownership, fewer fragile handoffs, more reliable account actions, and governance that remains where it belongs.
