See How Hire2Retire Can Drive Success for Your Organization |9th May 2025|

Easily Integrate UKG Pro (UltiPro)
With Active Directory, Entra ID,

Okta & Google Workspce with
Hire2Retire

Create this integration in minutes - no coding!



MEMIC Saves Millions!

More than 30 years after Maine Employer’s Mutual Insurance Company (MEMIC) started in Portland, Maine, the company has expanded to 510 employees, across five offices along the U.S. East Coast. This growth presented challenges for MEMIC’s HR and IT teams, who struggled to effectively onboard employees with UKGPro, Active Directory (AD), and Entra ID profiles. Hire2Retire helped MEMIC to integrate their HRIS systems to AD and saved 90% in direct costs of employee lifecycle management.

Intuitive No-Code UX

Incredibly Powerful

Customer Focused

For Business Users

Highly Scalable

Trusted and Reliable

Intuitive No-Code UX

For Business Users

Incredibly Powerful

Highly Scalable

Customer Focused

Trusted and Reliable

Want to learn more about this integration? 

Matt L

Matt L

CIO, American Elevator Group

“Hire2Retire is very easy to configure. It also allows for multiple configurations and complex situations. There is logic built-in that is very simliar to Excel's formulas. The product doesn't just create accounts and terminate accounts, but you have a lot of control over groups security, naming conventions, etc. There are also a large number of templates that you can customize for notifying users, managers, etc. on key events related to onboarding or offboarding.”

Frequently Asked Questions

Does it automatically create AD user account and Email?
Yes. The AD user account in your domain and the associated email address is created automatically by this integration. We also integrate with Office 365 to manage user account and other attributes including Office groups and SharePoint access.
What kind of sensitive information is processed by this Integration?
The data that this integration receives is often publicly available information like first name, last name, title, reports to, department, and location, etc. None of the aforementioned is sensitive or protected by any of the regulations like HIPAA or PII. During deep dive with customers, we have realized that the data this integration receives is presumed more sensitive than it really is.
How is employee information received from UltiPro?
UltiPro provides employee information either as an extract or via API calls. Most customers prefer employee extract as it is more reliable, efficient and cost-effective way to provide employee information and lifecycle updates.
How does it manage role-based access privilege control?
UltiPro to AD integration has a rule engine built into it. As a customer, you will provide rules which derive AD Security Groups based on its employee attributes or a combination of those. For example, job title, location and/or department may determine employee Security Group and therefore privileged access to enterprise systems.
How long does the end-to-end implementation take?
UltiPro to AD Integration is fully built Software as a Service (SaaS). It is configured to your needs, data mapping and business specific rules. We expect a maximum of two weeks of implementation assuming all the field mapping, and rules for security group, distribution lists and OU derivation are provided. Often, most of the implementation time beyond two weeks is spent on field mapping and rule definition at the customer’s end.
Does this integration handles timely terminations?
Yes. We understand handling of timely termination and removal of access is of utmost importance for the security, compliance and management of reputation risks. Terminations are processed in near real-time. Sensitive terminations can be handled by on-demand triggering of AD integration from UltiPro.
Does this integration support Azure AD or AWS hosted AD?
Yes. UltiPro to AD Integration supports on-premise, cloud or private cloud hosted Active Directory (AD). We also support Azure AD as well as AWS hosted Active Directory.
Can I add SSO or provision access to other enterprise systems?
Yes. You can use SSO or Identity Providers like Okta, Ping Identity, OneLogin, Centrify or Auth0 along with this integration. The SSO providers enforce Single Sign On and access control based on role-based access control (RBAC) definition created by this integration. We natively integrate with Microsoft SSO with Azure AD integration. We also offer provisioners to create and manage accounts in third party enterprise systems.
Is the UltiPro to AD integration fully automated and fully hosted?
Yes. The UltiPro to AD integration is fully automated near real-time integration. The Workday employee updates are pushed to RoboMQ and this integration processes the information as it is received 24×7. This integration is offered as fully hosted service by RoboMQ.
What data security control mechanisms are in place?
The data processed by RoboMQ is encrypted in transit and at rest. We do not store any of the employee data except the error logs. All the processing and handling of the data during the AD integration happens over the transient message queues. Furthermore, each customer has its own tenant on RoboMQ. This ensures tenant level data segregation and encryption.
Still have questions?