Skip to content
TargetFlo — ABA therapy center operations software
Integrations

Microsoft 365 for Therapy Centers: What Operations Teams Need

What therapy center operations teams need from Microsoft 365 and Entra ID — account lifecycle, groups, policy — and where TargetFlo's roadmap integration fits.

TargetFlo Team 6 min read
Microsoft 365 for Therapy Centers: What Operations Teams Need — TargetFlo blog

Roughly half of the therapy centers we speak with run on Microsoft 365. Their clinicians live in Outlook and Teams, their documents sit in SharePoint, and their identity — every login, every device policy — is governed by Entra ID. When those centers evaluate operations software, the first integration question is not about fax or eligibility. It is "will this work with our Microsoft tenant?"

This guide covers what operations teams actually need from Microsoft 365 for therapy centers, how Entra ID lifecycle management should connect to employee onboarding and offboarding, and where TargetFlo stands: Google Workspace lifecycle automation is live today, and Microsoft 365 is on the roadmap with a waitlist you can join from the workspace integrations page.

What is Entra ID employee lifecycle management?

Entra ID (formerly Azure Active Directory) is the identity service behind Microsoft 365. Employee lifecycle management in Entra ID means creating a user when someone is hired, assigning the licenses and groups their role requires, updating those assignments when the role changes, disabling the account when employment ends, and re-enabling it on return. Every downstream Microsoft service — Exchange mailbox, Teams membership, SharePoint access, Intune device policy — follows the user object and its group memberships.

For a therapy center, that makes Entra ID the single lever that controls who can see PHI in email, chat, and files. Pulling that lever late is the most common compliance gap we see.

What operations teams need, regardless of vendor

The operational requirements are the same whether your center runs Google or Microsoft:

NeedMicrosoft 365 mechanismGoogle Workspace mechanism
Create account on hireEntra ID user plus license assignmentWorkspace user in an org unit
Apply role-based policySecurity groups, conditional accessOrganizational units
Grant shared resourcesMicrosoft 365 Groups, SharePoint sitesGoogle Groups, shared drives
Block access on departureDisable sign-in, revoke sessionsSuspend account
Preserve recordsLitigation hold, mailbox retentionSuspended account data retained
Return or rehireRe-enable userReactivate account

The vocabulary differs; the lifecycle does not. What matters is whether those actions are triggered by a status change on the employee record or by someone remembering to open an admin console.

Where Microsoft 365 centers typically struggle

Groups drift from reality

A Teams channel for "Intake — North Location" accumulates members over two years. Half of them have changed roles. Nobody removes people from groups, because membership is not visible from the employee record where role changes are recorded. Group hygiene is the Microsoft equivalent of org unit hygiene in Google, and it decays just as fast without automation.

Disablement lags departure

Payroll knows the employee left. HR knows. Entra ID finds out when someone files a ticket. In centers without dedicated IT, that gap is measured in weeks. A disabled account takes seconds to create; the delay is entirely a process failure.

Licenses are never reclaimed

A disabled user who still holds a Microsoft 365 Business Premium license costs the center every month. Reclaiming licenses at offboarding is a small line item per employee and a meaningful one across a workforce with typical ABA turnover.

Conditional access is configured once and forgotten

Requiring multi-factor authentication and compliant devices for anyone in a "clinical staff" group is excellent — until new hires are placed in the wrong group and inherit no policy at all. Correct group assignment at provisioning time is what makes conditional access work.

What a lifecycle integration should do

The pattern TargetFlo runs today for Google Workspace, and is building for Microsoft 365, is straightforward:

  1. Employee record is the source of truth. Role, location, start date, and status live in the Workforce directory.
  2. Provisioning follows onboarding. When the record is activated, the account is created and placed in the group or org unit derived from role and location.
  3. Role and location changes update scope. Move a BT to a new site, and their group memberships and policy scope follow.
  4. Offboarding suspends immediately. Marking the employee as departed disables sign-in and removes group membership the same hour, while preserving mailbox and file data.
  5. Reactivation reuses the identity. Returning staff get their original account back, with training and consent history intact.

Read the full Google-side walkthrough in Google Workspace Integration for ABA Employee Lifecycle. The Microsoft 365 version will follow the same model using Microsoft Graph for user, group, and license operations.

What Microsoft-first centers can use in TargetFlo right now

The absence of account automation does not block the rest of the platform. Microsoft 365 organizations run TargetFlo today for:

  • The employee directory, with roles, locations, and status
  • Course-based training with tests and certificates, and versioned SOPs and consents with e-signatures, in the Training & Compliance module
  • Intake pipeline, fax inbox, eligibility checks, tasks, and the parent portal — none of which depend on the identity provider

Offboarding in these centers is a two-step process for now: mark the employee departed in TargetFlo, then disable the user in the Microsoft admin center. The roadmap integration collapses those into one.

Honest positioning on the roadmap

We label features carefully. Microsoft 365 and Entra ID lifecycle is coming soon, not live. It sits on the same roadmap as scheduling, session notes, claims submission, and the MCP server for Claude — all built into TargetFlo's architecture and rolling out in product releases. If Microsoft 365 automation is a deciding factor for your center, join the waitlist on the workspace integrations page and we will let you know when it ships.

Choosing between the ecosystems

For a center that has not yet committed, the honest answer is that both Google Workspace and Microsoft 365 support a Business Associate Agreement, both offer the identity controls a HIPAA-aware operation needs, and both will be automated by TargetFlo. Choose based on what your clinicians and leadership already use well. Retraining a workforce on a new email and document suite costs more than any difference between the two platforms.

If you are Google-first, lifecycle automation is available today. If you are Microsoft-first, the directory, training, and compliance tooling is ready now, and account automation is on its way.

  • Microsoft 365 for therapy centers
  • Entra ID employee lifecycle
  • ABA workforce management
  • Microsoft 365 HIPAA ABA
  • Google Workspace vs Microsoft 365 healthcare

See it in TargetFlo

Move intake out of the fax inbox

Book a 30-minute demo and we’ll map your referral flow to the 9-stage pipeline, connect your fax provider, and show eligibility checks at intake.

Book a Demo

FAQ

Frequently asked questions

Related articles

All articles

See TargetFlo on your own referral flow

Book a 30-minute demo. We map your current intake process to the 9-stage pipeline and show how fax, eligibility, tasks, and the parent portal fit together.