Entra ID already holds a better employee directory than your card tool does
Every organisation running Microsoft 365 has a complete, continuously maintained employee directory in Entra ID. It has the correct spelling of everyone's name, their current job title, their department, their office location, their work email, and usually their mobile number. It is updated by HR processes and joiner-mover-leaver automation that already exist and that somebody is already accountable for.
Re-entering that data into a digital business card platform — by CSV, by hand, or by asking employees to fill in their own profiles — creates a second, worse copy of a directory you already have. The second copy is wrong within a month, and nobody owns it. Reading directly from Entra means there is one directory, and the cards are a view of it.
This is also what makes a card rollout survive contact with an enterprise. IT teams will not adopt a tool that asks them to maintain a parallel roster, and they should not have to.
Choosing a card structure
The structure decides how many distinct card designs exist and who falls under each. Getting it right at the start avoids a migration later.
- All-in-one. A single design for the entire organisation. The correct default: one template to maintain, perfectly consistent branding, and no ambiguity about which design a given employee gets.
- By group. One design per value of a groupable attribute — most often department, but office or country work equally well. Choose this when brand guidelines genuinely differ across the business, such as a group with distinct subsidiary brands.
- By filter. A design applied to exactly the population matching your conditions. Useful for targeting a subset that no single attribute cleanly describes, such as customer-facing staff across several departments in specific regions.
Immediate versus first-login provisioning
Immediate provisioning creates every card the moment you apply the structure. Everyone has a card whether or not they have ever opened QRBold, which is what you want when the rollout is being announced company-wide with a deadline attached, or when cards are being printed onto badges in a single production run.
First-login provisioning creates a card the first time an employee signs in. In a 5,000-person directory where the realistic adoption is a few hundred people, this avoids generating 5,000 cards that mostly sit unused — which matters both for the dashboard staying navigable and for whatever your plan counts against.
Neither is universally right. Immediate suits a mandated rollout; first-login suits organic adoption. The setting is changeable, so starting with first-login during a pilot and switching to immediate at general availability is a reasonable path.
A note on sensitive directory attributes
Entra ID exposes far more about a person than a business card should carry. Employee ID, manager chain, on-premises SAM account name, hire date, and cost centre are all readable, and all of them are things a directory legitimately holds and a public card page has no business publishing.
QRBold flags these attributes as sensitive in the mapping interface rather than hiding them, because there are narrow legitimate uses — an internal-only card, or an employee ID printed on a badge for building access. Flagging keeps the decision explicit. The important property is that publishing a sensitive attribute to a public URL is never something that happens because a default was left alone.