A new employee becomes eligible only after the agreed identity and group checks.
Identity and SSO integration
Use company identity to govern who can use which locker.
When somebody joins, changes job or leaves, their approved identity and access rules can inform locker eligibility—without maintaining a separate list of locker users by hand.
- One identity source
- Role-aware eligibility
- Timely access removal
A department, site or job change can alter which storage or equipment they may use.
Offboarding can remove locker eligibility through the agreed deprovisioning process.
What Microsoft provides
Bring physical storage under the same identity decisions as workplace systems.
Microsoft describes Entra ID as its cloud identity and access management service. Its current documentation covers users, groups, authentication and application access. Microsoft Entra ID Governance guidance addresses onboarding, role changes, offboarding, entitlements and access reviews.
A proposed connection could use agreed identity or group information to govern employee workplace storage and controlled collection of shared equipment. The exact interface, data direction and supported events must be designed and confirmed.
That design should fit the wider workplace journey across buildings, teams and hybrid attendance patterns. For practical context, Vpod’s global FMCG case study shows the operational scale of IT asset lockers; it is not presented as evidence of a Microsoft Entra ID integration.
Official interface image from Microsoft Learn’s current user-management guidance.
Make identity useful at the locker
Turn “Alex works in IT at London HQ” into a controlled physical action.
The employee should not need a second locker account. The agreed design checks their current company identity and entitlement, then gives a simple result: access allowed, access denied or help required.
The identity-led locker journey
From role change to the right physical access.
This example shows an employee moving into the London IT Support team and becoming eligible to collect shared devices. It is an illustrative design, not evidence of deployed functionality.
- 01 · CHANGE
Receive the identity change
A person joins, moves team, changes site or reaches their leaving date.
- 02 · CHECK
Check current context
The agreed process checks identity, employment status, group, role or location.
- 03 · ENTITLE
Allow the right locker use
Workplace storage or approved equipment becomes available under the agreed rules.
- 04 · VERIFY
Confirm the person
The employee uses the agreed badge, phone, PIN or sign-in route at the point of use.
- 05 · USE
Open, collect or return
Only the permitted door and workflow are available to that employee.
- 06 · RECORD
Return the agreed event
Access, denial, collection, return or timeout can be passed to the chosen operational record.
When identity or access fails
If the employee cannot be matched, belongs to the wrong group, has no suitable locker or loses their credential, deny unsafe access and route the case to the named IT, security or facilities owner.
Running the rules across sites
Keep core identity and offboarding rules consistent while documenting local locker zones, equipment permissions, time windows, emergency processes and support contacts.
Illustrative workflow only. Names, roles, groups, locations and locker outcomes are examples. Supported identity methods, triggers and returned events must be confirmed during solution design.
What each role must decide
Clear ownership from directory to locker door.
IT Directors
Choose the authoritative identity source, provisioning method, support model and records that matter.
See how IT Directors can govern secure device issue and return →Security leaders
Define who may access each locker workflow, what happens after denial and how leavers are removed.
Review why unauthorised equipment access becomes harder to control at scale →Enterprise Architects
Set system boundaries, identifiers, data direction, failure behaviour and multi-site design principles.
Place identity inside Vpod’s wider connected-locker architecture →Remove avoidable identity work
Stop maintaining physical access separately from the employee lifecycle.
Compare the control model
Local locker accounts versus enterprise-governed identity.
See the physical workflow
Connect the employee, the locker and the operational record.
The Smart Estate Logistics Platform video shows how people interact with storage while the organisation retains visibility of availability and activity.
Watch Smart Estate Logistics Platform
Decisions to make before implementation
Agree exactly what identity controls—and what it does not.
Identity source
Confirm the tenant, stable identifier and authoritative joiner, mover and leaver events.
Eligibility rules
Define the groups, roles, locations and approvals that permit each locker workflow.
Authentication
Choose the supported sign-in, badge, phone or PIN route and fallback process.
Events returned
Decide which access, denial, collection, return and timeout events go where.
Deprovisioning
Set timing, retries and emergency revocation for movers, leavers and suspended accounts.
Data and ownership
Document data direction, retention, monitoring, support boundaries and multi-site exceptions.
Integration availability, supported triggers, data direction and delivery scope must be confirmed during solution design. Exact behaviour depends on the agreed Microsoft Entra ID, Vpod and smart-locker configuration. This page does not claim a native connector, certification, commercial relationship, customer deployment or functionality beyond the confirmed project scope.
Start with one identity decision
Show us how a real employee becomes eligible—or loses access—today.
Bring the identity source, sample groups and roles, current locker user process, offboarding timing, event requirements and exception owners.
Book an integration workshop







