Azure AD to Salesforce Sync
Automated Salesforce user provisioning and deprovisioning from Azure Active Directory so new starters get access immediately and leavers have it revoked the moment their Azure AD account is disabled.
When a new employee is added to Azure Active Directory, IT teams have to manually create their Salesforce account, set the correct profile and assign the right permissions before the user can work. When someone leaves, that Salesforce account has to be manually deactivated before access is revoked. Both steps are easy to forget or delay - meaning new starters wait for access and former employees retain Salesforce permissions they should not have. This Integration Pack monitors Azure Active Directory for user creation and status changes and automatically provisions or deactivates the corresponding Salesforce account. New users get Salesforce access the moment they are added to Azure AD. Disabled or removed Azure AD accounts trigger immediate Salesforce deactivation so access is never retained beyond the last working day.
Watch the agent run, end to end
Why deploy this use case
New users added to Azure Active Directory automatically receive a provisioned Salesforce account with the correct profile details - no manual IT provisioning required.
Disabling or removing an Azure AD user immediately deactivates the corresponding Salesforce account so access is revoked without any manual IT action.
Name, email, department and role sync from Azure AD to the Salesforce user record so both platforms always reflect the same current identity data.
New starters have Salesforce access the moment their Azure AD account is created so they can begin working without waiting for a manual provisioning ticket.
Former employees have Salesforce access revoked the moment their Azure AD account is disabled so no access is retained beyond the last working day.
IT teams stop manually creating and deactivating Salesforce accounts for every hire and departure - the integration handles provisioning and access control automatically.
Automated Salesforce User Provisioning and Deprovisioning from Azure Active Directory
See how IntelliPaaS monitors Azure Active Directory for user creation and status changes and automatically provisions or deactivates the corresponding Salesforce account in real time.
Questions teams ask
How quickly can we get the Azure AD to Salesforce Sync Integration Pack running?
Most teams are live the same day. Connect your ActiveDirectory and Salesforce accounts, confirm the field mapping and the agent starts running against your own data. There is no infrastructure to provision and nothing to deploy.
Do we need to write any code?
No. The Integration Pack ships with the trigger, the agent logic and the actions already configured. Everything is adjusted from the IntelliPaaS dashboard, so your operations team can own it without waiting on engineering.
How often does data sync between ActiveDirectory and Salesforce?
The agent runs on every qualifying event in ActiveDirectory, so records reach Salesforce within moments rather than waiting for an overnight batch. You can also put the Integration Pack on a schedule or trigger a run by hand when that suits your process better.
What happens if a record fails to sync?
Failed runs are retried automatically, and anything still unresolved is held in a review queue with the full error trace attached, so nothing is dropped silently. Your team is alerted and can replay the record once the cause is cleared.
Can we customise the field mapping?
Yes. Every field mapped between ActiveDirectory and Salesforce is editable, and you can layer on your own conditions, filters and transformations without leaving the Integration Pack.

