Almost every organization already lives in Entra ID. Accounts are created when people join, group memberships change when they switch roles, and everything is disabled the moment they leave. That lifecycle governs email, files and applications reliably.
Physical keys sit outside it. The person who disables a leaver’s account in Entra ID is usually not the person who manages the key cabinet, and the two actions rarely happen on the same day. In practice this means:
For critical entities under NIS2 and the CER Directive, that gap between digital and physical access is exactly what regulators expect you to close.
Key2XS is middleware that treats iLOQ key rights the way Entra ID treats application access: assigned through groups, driven by lifecycle events, and always auditable.
| From Microsoft Entra ID | To iLOQ via Key2XS |
|---|---|
| Users (joiners, movers, leavers) | Key holders created, updated or deactivated |
| Group and role memberships | Key rights and access to lock groups |
| Account disablement and expiration | Immediate withdrawal of key rights |
| Assignment history | Documented authorization behind every key |
Changes flow through in near real-time, so revoking access in Entra ID does not wait for a nightly batch to reach your keys.
Key2XS is used where physical access affects public safety, service continuity or regulatory compliance: utilities, government, transport, healthcare and industry.
Entra ID has a powerful Graph API, and iLOQ has an API too, so a custom integration is technically possible. In practice it means owning connector code against two evolving APIs, building your own audit layer, handling every edge case in the joiner-mover-leaver flow, and maintaining it all for years. Key2XS delivers this as a maintained platform: