<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=7847562&amp;fmt=gif">
Home > Integrations

Manage iLOQ keys from Microsoft Entra ID

Key2XS connects Microsoft Entra ID (formerly Azure Active Directory) to the iLOQ digital locking system. Group memberships and roles in Entra ID are automatically translated into iLOQ key rights, so physical access follows the same identity lifecycle you already run for Microsoft 365 and your business applications.

Request a demo

Your identity lifecycle stops at the front door

Almost every organization already lives in Entra ID. Accounts are created when people join, group memberships change when they switch roles, and everything is disabled the moment they leave. That lifecycle governs email, files and applications reliably.

Physical keys sit outside it. The person who disables a leaver’s account in Entra ID is usually not the person who manages the key cabinet, and the two actions rarely happen on the same day. In practice this means:

For critical entities under NIS2 and the CER Directive, that gap between digital and physical access is exactly what regulators expect you to close.

Group-based physical access, the Entra ID way

Key2XS is middleware that treats iLOQ key rights the way Entra ID treats application access: assigned through groups, driven by lifecycle events, and always auditable.

How it works

  1. Connect. Key2XS connects to your Entra ID tenant and your iLOQ environment through their standard APIs. A standard integration is live in under two hours, with no custom development.
  2. Map. Entra ID groups and roles are mapped to iLOQ key rights and lock groups. A security group like “Facilities - Technical Rooms” can correspond to exactly those doors and cylinders in iLOQ, in the same way it would grant an application role.
  3. Orchestrate. When a user is added to or removed from a mapped group, or their account is disabled, Key2XS applies the change to their iLOQ key rights in near real-time. Blocking a leaver in Entra ID withdraws their physical access in the same movement.
  4. Prove. Every key right traces back to an identity, a group and a moment in time, in one tamper-evident audit trail.

What synchronizes between Entra ID and iLOQ

From Microsoft Entra ID To iLOQ via Key2XS
Users (joiners, movers, leavers) Key holders created, updated or deactivated
Group and role memberships Key rights and access to lock groups
Account disablement and expiration Immediate withdrawal of key rights
Assignment history Documented authorization behind every key

Changes flow through in near real-time, so revoking access in Entra ID does not wait for a nightly batch to reach your keys.

Built for critical environments

Key2XS is used where physical access affects public safety, service continuity or regulatory compliance: utilities, government, transport, healthcare and industry.

Why not build this yourself?

Entra ID has a powerful Graph API, and iLOQ has an API too, so a custom integration is technically possible. In practice it means owning connector code against two evolving APIs, building your own audit layer, handling every edge case in the joiner-mover-leaver flow, and maintaining it all for years. Key2XS delivers this as a maintained platform:

Frequently asked questions

The Microsoft Entra ID and iLOQ integration, answered.

See Entra ID and iLOQ working together

Get a guided walkthrough of how identity, groups and physical keys come together in one auditable flow.