Lifecycle timelineIt all starts in Stratus (our HR system)
1
Stratus (HR)
source of truth
2
New Hire
employee created
3
Entra ID
account + groups
4
Intune
policies + apps
5
Autopilot
zero-touch enroll
6
Fulfillment Center
ship · receive · dispose
7
Active Employee
device assigned
8
Department Change
role moves
9
Device Replacement
broken / request
10
Leaving Company
offboarding
11
Conditional Access
block sign-in
12
Intune Wipe
remote erase
13
License Removed
M365 reclaimed
14
Reassigned
next employee
Scroll the diagram, press → , or click Next to advance
1
Stratus (HR)
It all starts in Stratus (our HR system)
Stratus is our single source of truth for every employee — hires, departments, role changes, terminations. Nothing about a person is entered manually in IT systems. Every downstream change flows from here.
Human in the loop · HR team owns Stratus. People decide who joins, moves or leaves — automation only reacts to what they record.
User Lifecycle
Automation
Device State
Fulfillment Ops
System
Human in the loop
Is this real? Yes — here's how we build it
Setup roadmap · 7 phases · 4 weeks
Everything in the diagram above is native Microsoft 365 functionality. You need Business Premium / E3 / E5 licenses (Entra ID P1 + Intune) and tenant admin access. No custom code, no third-party platform.
Microsoft 365 E3/E5Entra ID P1+IntuneStratus HRPower Automate
- 1HR + ITPhase 1 · Week 1Identity foundation — Stratus → Entra ID
- Standardize HR attributes in Stratus (employeeType, department, location, manager, start/end date)
- Wire Stratus → Entra ID via SCIM or scheduled Graph sync
- Define Joiner / Mover / Leaver workflows in Entra ID Governance (Lifecycle Workflows)
Watch out · Stratus integration is the #1 risk — confirm SCIM support or build a Logic App. - 2ITPhase 2 · Week 1Dynamic groups
- Create groups keyed off employeeType, department, location
- Entra ID → Groups → New group → Dynamic User
- Never assign policies to individual users — always to groups
- 3ITPhase 3 · Week 2License automation
- Assign M365 licenses to All-Employees dynamic group
- Group membership change auto-grants/revokes seats
- Stops paying for inactive users automatically
- 4SecurityPhase 4 · Week 2Conditional Access
- Require MFA, block legacy auth, enforce compliant devices
- Target policies by dynamic group, not individuals
- Always keep a break-glass admin account
Watch out · CA misconfiguration can lock everyone out — test in report-only first. - 5ITPhase 5 · Week 2–3Intune + Autopilot
- Register device hashes with reseller (OEM uploads to your tenant)
- Build Autopilot deployment profile + device categories
- Create dynamic device groups, assign apps & compliance policies
Watch out · Hashes must be registered before devices ship — coordinate with reseller. - 6Ops + ITPhase 6 · Week 3Fulfillment center workflow
- Power Automate flow: new All-Employees member → fulfillment ticket
- Fulfillment staff pick device, mark category in Intune, ship
- Returns: leaver event → wipe + Autopilot reset → category flipped to Ready
Watch out · Wipe + Autopilot reset gets a returned device ready for the next hire in ~30 min. - 7IT + HRPhase 7 · Week 4Close the loop — Lifecycle Workflows
- Joiner: welcome email, device shipment ticket, training assignment
- Mover: re-evaluate groups, transfer manager, update CA scope
- Leaver: disable, revoke tokens, wipe, return shipment, transfer OneDrive
Watch out · Lifecycle Workflows requires Entra ID Governance (P2) — or replicate with Logic Apps.
Timeline
4 weeks end-to-end
Aggressive but doable — parallelize Phases 1–2 and 3–4.
What we keep human
Decisions & exceptions
Hiring, terminations-for-cause, repair vs replace, exec onboarding.
What we automate
The plumbing
Accounts, groups, policies, licenses, wipes, shipments tickets.