Starting point

IT onboarding
Provision equipment and access for new employees
As soon as a new hire's role and start date are known, the required devices, software accounts and access rights are derived automatically and provisioned in time for the first day. IT only has to decide on non-standard equipment, instead of setting up every access manually.
Process architecture
From role to a fully provisioned workplace.
The process takes the personnel data of a newly hired person, derives the required standard equipment from role and department, and sets up devices, accounts and access rights in time for the start date. Deviations from the standard equipment go to IT for review; the standard case runs through without manually creating every single access.
01Input
Open quotes and their context come together.
The process starts with silence rather than a message: a quote that has had no answer for days. The leading system supplies the quote, its deadline and the contact, together with the correspondence already attached to the case.
2 Steps
02Process
The right message is derived from the state of the case.
The draft comes from the quote itself, not from a template full of placeholders. The rules then check whether a follow-up is allowed at all; anything outside the agreed frame goes to a salesperson.
4 Steps
03Output
The message goes out and the case stays traceable.
The follow-up sits in the same conversation as the quote, sales sees the current state without asking, and every attempt is documented on the case.
3 Steps
Source01Take over new personnel data
Role, department, location and start date of a newly hired person are taken from the HR system as soon as the contract is signed – via Microsoft Entra ID, Google Workspace Admin or a custom identity management system, depending on the environment.Details
Take over new personnel data
Role, department, location and start date of a newly hired person are taken from the HR system as soon as the contract is signed – via Microsoft Entra ID, Google Workspace Admin or a custom identity management system, depending on the environment.
- Microsoft Graph API
- SharePoint API
- Derive standard equipment
Data02Derive standard equipment
Role and department are matched against a stored template to derive which devices, software accounts and access rights the person needs by default.Details
Derive standard equipment
Role and department are matched against a stored template to derive which devices, software accounts and access rights the person needs by default.
- Azure AI Document Intelligence
- Mistral OCR
- Dataverse API
- Create accounts and access
Action03Create accounts and access
The user account, mailbox and the software accounts defined in the template are created automatically, with the matching permission groups.Details
Create accounts and access
The user account, mailbox and the software accounts defined in the template are created automatically, with the matching permission groups.
- Power Automate
- Azure Functions
- Microsoft Graph API
- Check for deviations
Decision04Check for deviations
If the requested equipment deviates from the standard template, for example through an additional system or extended rights, the case counts as needing clarification.Details
Check for deviations
If the requested equipment deviates from the standard template, for example through an additional system or extended rights, the case counts as needing clarification.
- Azure OpenAI GPT
- Anthropic Claude
- AI Builder
- Trigger device provisioningstandard case
- Approve non-standard equipmentexception
Approval05Approve non-standard equipment
For a deviation, IT reviews the request and approves the additional equipment or declines it with a reason.Details
Approve non-standard equipment
For a deviation, IT reviews the request and approves the additional equipment or declines it with a reason.
- Teams Adaptive Cards
- Power Apps
- Trigger device provisioningafter approval
System06Trigger device provisioning
The devices intended for the new person are reserved from stock or a procurement request is triggered, in time for the start date.Details
Trigger device provisioning
The devices intended for the new person are reserved from stock or a procurement request is triggered, in time for the start date.
- Dynamics 365 API
- Azure Service Bus
- Activate access
- Inform the responsible people
Result07Activate access
All accounts and access rights are activated automatically on the start date, not earlier and not later.Details
Activate access
All accounts and access rights are activated automatically on the start date, not earlier and not later.
- Power BI API
- Teams Webhook
- Log the equipment
Result08Inform the responsible people
Managers and IT receive confirmation that equipment and access are ready for the start date, along with an overview of the device handover.Details
Inform the responsible people
Managers and IT receive confirmation that equipment and access are ready for the start date, along with an overview of the device handover.
- Power BI API
- Teams Webhook
Result09Log the equipment
Every account created, every device assigned and every approval is documented with a timestamp, as a basis for later return or adjustment.Details
Log the equipment
Every account created, every device assigned and every approval is documented with a timestamp, as a basis for later return or adjustment.
- Power BI API
- Teams Webhook
System landscape
The same process in three environments.
- Microsoft
Microsoft Graph API
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
SharePoint API
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Azure AI Document Intelligence
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Mistral OCR
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Dataverse API
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Power Automate
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Azure Functions
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Azure OpenAI GPT
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Anthropic Claude
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
AI Builder
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Teams Adaptive Cards
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Power Apps
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Dynamics 365 API
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Azure Service Bus
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Power BI API
Möglicher Baustein für die Microsoft-Systemvariante.
- Microsoft
Teams Webhook
Möglicher Baustein für die Microsoft-Systemvariante.
- Interfaces in use
Google Workspace Admin SDK
Google environment: creates user accounts in the Google Workspace Admin console and assigns groups.
- Interfaces in use
REST API
Individual environment: connects the custom identity management system with the HR system and device management.
- Interfaces in use
SCIM-Protokoll
Creates accounts in connected business applications automatically to the same standard, independent of the chosen environment.
- Interfaces in use
Microsoft Intune
Microsoft environment: configures and manages the assigned devices centrally.
- Interfaces in use
Google Endpoint Management
Google environment: configures and manages the assigned devices centrally.
- Possible apps & platforms
Microsoft Entra ID und Microsoft Intune
Account creation, rights management and device management in the Microsoft environment.
- Possible apps & platforms
Google Workspace Admin-Konsole
Account creation and rights management in the Google environment.
- Possible apps & platforms
Identitätsmanagementsystem
Leading system for accounts and rights in the individual environment.
- Possible apps & platforms
Gerätemanagement-Software
Management and assignment of devices in the individual environment.
Implementation in context
What the process does and what it deliberately leaves to people.
The process creates accounts and access according to a fixed template; it does not decide on new access rights outside that template. Every deviation – an additional system, extended permissions – goes to IT for a deliberate approval.
The environment determines the tools, not the process. In a Microsoft 365 environment account creation and device management run through Microsoft Entra ID and Intune, in a Google Workspace environment through the Google Workspace Admin console, in a self-hosted environment through a custom identity management system. Which variant fits depends on where the company already runs its user management.
Access is deliberately activated only on the start date, not earlier. That way there is no window in which an account is already usable while the person has not officially joined the company yet.
Every account creation, device handout and approval is logged. That eases not just traceability but also the later return or adjustment of equipment, for example on a role change.
Target picture
As soon as role and start date are known, accounts, access rights and devices are derived automatically from a stored template and provisioned in time. IT only deals with genuine deviations from the standard equipment, not with every single account.
Expected benefits
- Accounts and access are ready automatically on the start date, instead of after days of email coordination.
- IT only deals with genuine deviations from the standard equipment.
- Access is not activated before the official start date, avoiding an unnecessary security risk.
- Managers automatically see that equipment and access are ready for the first day.
- Every account creation and device handout stays traceably documented, including for later return.
- The process adapts to the existing environment instead of making an additional identity management tool a precondition.
Prerequisites to start
- 01An HR system from which role, department and start date of a new person can be taken automatically.
- 02A stored template defining which devices, accounts and access rights belong to the standard equipment per role or department.
- 03An identity or user management system in which the process is allowed to create accounts.
- 04A device stock or procurement process to which the process can hand off a reservation or order.
- 05A decision on the environment: Microsoft 365, Google Workspace or self-hosted – and the matching access rights.
Your next step
Which process costs your team unnecessary time every day?
Give us a short outline. We will tell you honestly where automation is useful—and where it is not.






