KeyForge AI
Integrations · Microsoft Entra

Access governance for Microsoft Entra ID & Entra ID Governance

Resolve nested group membership and directory role assignments, and bring them into the same rule set that evaluates your ERP entitlements.

The access model

How Microsoft Entra grants access

Rules evaluate the effective permission after inheritance is resolved — then normalise it, so the same rule can reach into another platform.

Access is granted by

Directory role and group

The object an administrator assigns in Microsoft Entra.
Resolved to

Role assignment and group membership

The atomic permission we evaluate rules against, after nesting and inheritance are flattened.
Data dimension

Administrative unit

Evaluated alongside functional access, so scope is part of the rule rather than a filter applied afterwards.

In practice

What this catches

01

Finance file-share administration paired with payment creation in an ERP

02

Privileged directory roles held alongside transactional access

03

Nested groups resolved to effective membership

The conflicts that matter most rarely sit inside one system. Pair Microsoft Entra with the directory, a payments gateway or a second ERP and the combination becomes visible — which is the point of a cross-application rule.

Also supported

Pairs with

See it against your Microsoft Entra estate.

Book a technical demo, or start with a read-only risk assessment.