Case Study: Workday to Entra ID Provisioning for a Multinational Enterprise
At a glance
- Client type: Multinational enterprise with New Zealand business operations
- Problem: Joiner, mover, and leaver processes needed stronger integration between Workday, Entra ID, and Active Directory.
- Finding: Attribute mapping, transformation, email generation, provisioning, deprovisioning, and SSO all needed to work together.
- Outcome: Automated identity lifecycle integration delivered and still in use years later.
- Related service: Security and identity / identity lifecycle automation
Problem
A multinational enterprise needed Workday to act as the HR source for identity lifecycle events across Entra ID and Active Directory.
The organisation wanted a more reliable way to provision users, update attributes, support movers, and deprovision accounts without relying on manual steps that could lag behind HR changes.
Context
HR-driven provisioning has to be precise. A small mapping or transformation mistake can create incorrect accounts, poor naming, missing access, or delayed leaver processing.
The integration also needed to support SSO and fit the organisation's existing identity model, not force every process to change at once.
The challenge was not only technical. It required clear communication, requirements gathering, agreement on ownership, and careful mapping between HR data and identity objects.
What was accomplished
Our team helped design and implement the integration between Workday, Entra ID, and Active Directory.
This ensured the implementation was not just technically functional, but aligned to the business lifecycle process.
| Area | Work completed |
|---|---|
| Source data | Used Workday as the HR source for user lifecycle information. |
| Attribute mapping | Mapped Workday attributes into Entra ID and Active Directory requirements. |
| Transformation | Handled transformation logic so source data produced usable identity attributes. |
| Email generation | Supported email and identity naming requirements as part of provisioning. |
| Provisioning | Automated creation and updates for users based on HR events. |
| Deprovisioning | Supported leaver handling so access could be removed more reliably. |
| SSO | Aligned the integration with the organisation's sign-in and access model. |
Key decisions and trade-offs
The work had to balance automation with control. HR data needed to drive the identity lifecycle, but the mapping had to be explicit enough that operations teams could understand and support it.
The integration also needed to work with existing directory requirements while improving the process for future identity changes.
Result
The Workday, Entra ID, and Active Directory integration was delivered and remained in use years later.
The organisation gained a stronger identity lifecycle process for joiners, movers, and leavers, with less reliance on manual updates and a clearer connection between HR records and identity state.
A key success measure was the durability of the solution. Four years after implementation, the organisation is happily using the same core logic for data flow, transformations, and email generation.
That is a strong sign that the design was practical, stable, and aligned to real business requirements.
Conclusion
Identity lifecycle automation only works when the HR source, directory model, attributes, and support process all line up.
A practical security and identity review can turn Workday and Entra ID provisioning from a fragile integration into a long-term operating capability.
Related
Book a discovery call
If any of this sounds familiar, book a quick call and have a chat with one of our senior security and identity consultants with 20+ years of enterprise IT experience.
This is a space where you will not hit first-line support or people without relevant enterprise experience.
Turn hidden access risk into clear, practical remediation.