← All case studies

Automating Employee Onboarding and Offboarding from Ticket to Tenant

August 15, 2026
Entra IDAutomationPowerShellMicrosoft GraphPower AutomateKey VaultMicrosoft 365Exchange OnlineMicrosoft Teams

Problem

Manual, ticket-by-ticket onboarding and offboarding that depended entirely on whoever picked up the ticket

Outcome

A self-driving, ticket-triggered lifecycle process that provisions, deprovisions, and reactivates accounts without a human running a script by hand

The Problem

Onboarding and offboarding both ran through the same path: a service desk ticket, worked by hand. For a new hire, that meant manually creating the account, assigning licenses, and building out group memberships, one step at a time, with no guarantee two different people handled it the same way. It also meant remembering things that don’t show up on any checklist: whether this name had worked here before, whether their old mailbox had been converted to shared during that earlier departure, whether a phone number was even available for their office.

Offboarding carried more risk. A missed group removal, a license left assigned, or a mailbox nobody thought to hand off could leave a real security gap behind, and the outcome depended entirely on whoever picked up the ticket that day. Sensitive separations needed an entirely different path: an involuntary or confidential termination shouldn’t route through a shared support queue where anyone on the service desk could see it.

The Approach

Power Automate handles intake, watching for onboarding and offboarding tickets, routing them for approval, and kicking off the automation once approved. Everything downstream runs unattended, authenticated through an app registration and a certificate in Key Vault rather than a signed-in admin account, so no password or long-lived token sits in a script anywhere.

Provisioning happens through PowerShell against the Microsoft Graph API. For a new hire, the automation pulls office, address, and area code from a maintained directory, checks license availability before starting and falls back to a base tier if a specific add-on isn’t available, and assigns a phone number, ordering a new one directly from the carrier if none is free in the right area code and writing it back into the person’s contact card once it lands.

Returning employees get their own path. A name match against an existing account triggers a reactivation instead of a duplicate: password reset, stale multi-factor registrations cleared, and a mailbox converted back from shared if a previous offboarding left it that way.

Nothing finishes without a confirmed manager, matched by name or email with disambiguation when more than one match comes up. Once the account is built, its details and a temporary password, required to change at first sign-in, go out in an email to the manager as a final human check before the account goes live.

Offboarding runs the same idea in reverse, with more at stake: disabling sign-in and revoking active sessions immediately, removing the manager relationship, and stripping every group membership, Microsoft 365, mail-enabled security, distribution, and standard security groups, before licenses come off.

Confidential separations skip the standard service desk queue and route directly to the manager instead of a shared inbox. Departures don’t always happen one at a time either, so the same workflow can process a batch in a single run.

Every onboarding and offboarding closes with a summary tied back to the originating ticket, a clear record of what happened, not just a memory of what an admin meant to do.

Technical Highlights

The automation deliberately separates the broad directory-write permissions needed for provisioning and deprovisioning from the narrower send-only permission needed for the final notification step, scoped to a single mailbox. A compromised or misconfigured piece of the automation can’t do more than the phase it’s actually responsible for.

For returning employees, the process reactivates the original account rather than creating a new one. That preserves the person’s original identity object and history, rather than starting them over as if they’d never worked there before.

HR-driven provisioning through a standard like SCIM was on the table and set aside. Most HR platforms charge a premium for that level of integration, and it would have moved account creation and deprovisioning, a security-sensitive process, out of IT’s hands and into whatever logic the HR system’s connector happens to support. Keeping it in-house kept the cost down and the process under IT’s direct control.

The Outcome

What used to be a manual, ticket-by-ticket process that lived or died on one person’s attention to detail became a self-driving workflow: a ticket comes in, gets approved, and the automation handles the rest without anyone needing to remember every step or sit down and run a script by hand. The two directions also talk to each other: a returning employee’s onboarding automatically finds and reverses whatever their last offboarding left behind, rather than the two processes existing as disconnected one-off scripts. The result is a consistent, secure, and auditable process regardless of who submitted the ticket, how many people need handling at once, or whether someone’s arriving, leaving, or coming back.

Have a similar project in mind?

Let's talk about what your environment needs, no obligation, no pressure to commit.

Contact me