Home > Identity platforms

Microsoft Entra ID and Key2XS: one lifecycle, every key system

Microsoft Entra ID is the identity platform behind Microsoft 365 and Azure, and for most organizations it is already the system that decides who is allowed what. Key2XS extends that decision to the physical estate, so the groups you maintain in Entra ID govern iLOQ cylinders, ASSA ABLOY CLIQ keys and ABLOY PULSE locks as well as applications.

Request a demo

What Microsoft Entra ID is

Microsoft Entra ID is Microsoft's cloud identity and access management service, renamed from Azure Active Directory in 2023. It holds the accounts, credentials and group memberships that sign people in to Microsoft 365, Azure and the SaaS applications connected to it through single sign-on. For organizations already standardized on Microsoft, it is the default place where identity lives.

The parts that matter for access decisions:

Entra ID is deliberately broad on the digital side. What it does not have is a way to reach a mechanical or electronic key.

Where the Entra ID lifecycle stops

Accounts are created when people join, group memberships change when they move, and everything is disabled the moment they leave. That lifecycle governs mail, files and applications reliably. Physical keys sit outside it: the person who blocks a leaver in Entra ID is usually not the person who manages the key cabinet, and the two actions rarely happen on the same day.

For critical entities under NIS2 and the CER Directive, that gap between digital and physical access is exactly what regulators expect you to close.

How Key2XS connects to Entra ID

Key2XS registers as an application against your Entra ID tenant and subscribes to change notifications on the objects that matter. There is no agent to deploy in your tenant and no schema extension to install.

ProtocolMicrosoft Graph API with Graph webhook subscriptions
AuthenticationOAuth 2.0 (MSAL)
DirectionBidirectional: identities in, provisioning status back
SynchronizationReal-time, driven by Graph change notifications

Connect, map, orchestrate, prove

  1. Connect. Key2XS connects to your Entra ID tenant over Microsoft Graph and to each key system over its own API. A standard integration is live in under two hours, with no custom development.
  2. Map. Entra ID groups, roles and access packages are mapped to key rights and lock groups. A security group like “Facilities, Technical Rooms” can correspond to exactly those doors and cylinders, in the same way it would grant an application role.
  3. Orchestrate. When a user is added to or removed from a mapped group, or their account is disabled, Key2XS applies the change to their key rights in real-time. Blocking a leaver in Entra ID withdraws their physical access in the same movement.
  4. Prove. Every key right traces back to an identity, a group and a moment in time, in one tamper-evident audit trail.

What moves between Microsoft Entra ID and Key2XS

From Microsoft Entra ID To your key systems via Key2XS
Users (joiners, movers, leavers) Key holders created, updated or deactivated
Group, role and access package membership Key rights and access to lock groups
Account disablement and expiration Immediate withdrawal of key rights
Assignment history Documented authorization behind every key

One source of truth, every key system

The point of connecting Entra ID to Key2XS is not a single lock brand. Entra ID becomes the one place where physical access is decided, and Key2XS carries that decision to whichever key systems your sites actually run. Most organizations have more than one: a digital locking system at the head office, electronic keys on the network, mechanical high-security cylinders on the perimeter.

Key system under governance How Key2XS drives it
iLOQ S5 and S50
Self-powered digital cylinders (S5) and Bluetooth/NFC phone keys (S50).
REST API. Key holders, key rights and key validity provisioned per person, with 29 independent sync operations.
ASSA ABLOY eCLIQ
Electronic cylinders, padlocks and programmable keys.
SOAP API through CLIQ Web Manager, secured with mutual TLS. Full lifecycle, event-driven and batch.
ASSA ABLOY PROTEC2 CLIQ
High-security locking combining rotating disc technology with electronic identification.
SOAP API through CLIQ Web Manager, secured with mutual TLS. Full lifecycle, event-driven and batch.
ASSA ABLOY CLIQ Remote
Remote key updates through wall programmers, desktop units or the CLIQ Connect Bluetooth app, so keys never have to come back to a desk.
SOAP API through CLIQ Web Manager, secured with mutual TLS. Validity windows refreshed in the field.
ABLOY PULSE
Self-sustaining locks that harvest their energy from key insertion. No batteries, no wiring.
SOAP API through CLIQ Web Manager, secured with mutual TLS. Full lifecycle, event-driven and batch.

Key2XS is certified by ASSA ABLOY for its locking system integrations. One mapping in Entra ID can therefore span brands: a single role or group grants the iLOQ cylinders in one building and the eCLIQ padlocks on a remote site, revoked together the moment Entra ID says so.

The same holds on the identity side. Key2XS also connects to SailPoint Identity Security Cloud, Okta, One Identity Manager and OpenText Identity Manager, and to any system that can speak SCIM 2.0, so a landscape with more than one identity platform still resolves to one physical access model. See the integrations overview for the full picture.

Built for critical environments

Key2XS is used where physical access affects public safety, service continuity or regulatory compliance: utilities, government, transport, healthcare and industry.

Why not build this on Graph yourself?

Microsoft Graph is well documented and the key systems have APIs too, so a custom integration is technically possible. In practice it means owning connector code against several evolving APIs at once, building your own audit layer, handling every edge case in the joiner-mover-leaver flow, and maintaining it for years while it quietly becomes critical infrastructure. Key2XS delivers this as a maintained platform:

Frequently asked questions

Microsoft Entra ID and Key2XS, answered.

See Entra ID governing your keys

Get a guided walkthrough of how groups, lifecycle events and physical keys come together in one auditable flow.