Microsoft Entra ID is Microsoft's cloud identity and access management service, renamed from Azure Active Directory in 2023. It holds the accounts, credentials and group memberships that sign people in to Microsoft 365, Azure and the SaaS applications connected to it through single sign-on. For organizations already standardized on Microsoft, it is the default place where identity lives.
The parts that matter for access decisions:
Entra ID is deliberately broad on the digital side. What it does not have is a way to reach a mechanical or electronic key.
Accounts are created when people join, group memberships change when they move, and everything is disabled the moment they leave. That lifecycle governs mail, files and applications reliably. Physical keys sit outside it: the person who blocks a leaver in Entra ID is usually not the person who manages the key cabinet, and the two actions rarely happen on the same day.
For critical entities under NIS2 and the CER Directive, that gap between digital and physical access is exactly what regulators expect you to close.
Key2XS registers as an application against your Entra ID tenant and subscribes to change notifications on the objects that matter. There is no agent to deploy in your tenant and no schema extension to install.
| From Microsoft Entra ID | To your key systems via Key2XS |
|---|---|
| Users (joiners, movers, leavers) | Key holders created, updated or deactivated |
| Group, role and access package membership | Key rights and access to lock groups |
| Account disablement and expiration | Immediate withdrawal of key rights |
| Assignment history | Documented authorization behind every key |
The point of connecting Entra ID to Key2XS is not a single lock brand. Entra ID becomes the one place where physical access is decided, and Key2XS carries that decision to whichever key systems your sites actually run. Most organizations have more than one: a digital locking system at the head office, electronic keys on the network, mechanical high-security cylinders on the perimeter.
| Key system under governance | How Key2XS drives it |
|---|---|
| iLOQ S5 and S50 Self-powered digital cylinders (S5) and Bluetooth/NFC phone keys (S50). |
REST API. Key holders, key rights and key validity provisioned per person, with 29 independent sync operations. |
| ASSA ABLOY eCLIQ Electronic cylinders, padlocks and programmable keys. |
SOAP API through CLIQ Web Manager, secured with mutual TLS. Full lifecycle, event-driven and batch. |
| ASSA ABLOY PROTEC2 CLIQ High-security locking combining rotating disc technology with electronic identification. |
SOAP API through CLIQ Web Manager, secured with mutual TLS. Full lifecycle, event-driven and batch. |
| ASSA ABLOY CLIQ Remote Remote key updates through wall programmers, desktop units or the CLIQ Connect Bluetooth app, so keys never have to come back to a desk. |
SOAP API through CLIQ Web Manager, secured with mutual TLS. Validity windows refreshed in the field. |
| ABLOY PULSE Self-sustaining locks that harvest their energy from key insertion. No batteries, no wiring. |
SOAP API through CLIQ Web Manager, secured with mutual TLS. Full lifecycle, event-driven and batch. |
Key2XS is certified by ASSA ABLOY for its locking system integrations. One mapping in Entra ID can therefore span brands: a single role or group grants the iLOQ cylinders in one building and the eCLIQ padlocks on a remote site, revoked together the moment Entra ID says so.
The same holds on the identity side. Key2XS also connects to SailPoint Identity Security Cloud, Okta, One Identity Manager and OpenText Identity Manager, and to any system that can speak SCIM 2.0, so a landscape with more than one identity platform still resolves to one physical access model. See the integrations overview for the full picture.
Key2XS is used where physical access affects public safety, service continuity or regulatory compliance: utilities, government, transport, healthcare and industry.
Microsoft Graph is well documented and the key systems have APIs too, so a custom integration is technically possible. In practice it means owning connector code against several evolving APIs at once, building your own audit layer, handling every edge case in the joiner-mover-leaver flow, and maintaining it for years while it quietly becomes critical infrastructure. Key2XS delivers this as a maintained platform: