Access rights have to
keep pace with the tasks.

Central identities connect login and permissions across several applications.

New employees need accounts in many systems, while old rights remain after a change of role. Separate passwords and inconsistent groups make the overview harder. Reliable administration therefore needs agreed roles and clear procedures for joining, changing and leaving. Single sign-on and multi-factor login have to fit the applications in place.

Start now at no cost

In a free first conversation we look at your user management and place what comes first.

Arrange a first conversation

Scope of services

Sign in to applications together

Single sign-on connects suitable systems with one central identity.

Organise rights by task

Users, groups and roles form the basis for access.

Secure sign-in further

Multi-factor authentication complements the agreed access procedures.

One identity for many applications

IQstruct Engineering sets up directory and identity services and connects applications.

Active Directory, Microsoft Entra ID, LDAP and Keycloak belong to the range we use. Single sign-on, role and permission concepts and multi-factor authentication are coordinated with the existing infrastructure, cloud or on-premises operation and the protection requirements.

Custom web software, cloud applications and AI systems can also be connected to the identity services. For confidential knowledge areas, we additionally clarify which content a role may reach.

Person working at a monitor and a notebook with source code

Identities

Rights follow the role, even when it changes

Users, groups and roles are maintained centrally and apply in all connected applications.

Approach in the project

  1. An administrator plans the directory structure, roles and applications on the screenAi

    1

    Plan identities

    Directory services, roles and applications are defined in the requirements discussion.

  2. Two administrators set up the directory, roles and single sign-on on the screenAi

    2

    Set up the directory service

    Directory, roles and single sign-on connections are configured.

  3. An employee opens her company applications in the portal after one sign-inAi

    3

    Use single sign-on

    Employees sign in once and reach the connected applications.

  4. Two administrators create accounts and permissions for a new person on the screenAi

    4

    Onboard employees

    New people receive defined accounts and suitable permissions.

Identity services

Active Directory and LDAP

For environments with their own in-house directory service.

Microsoft Entra ID

For Microsoft 365 and cloud environments.

Keycloak

For open identity management with single sign-on in your own applications.

IT/OT

Looking after infrastructure and protective measures together

Changes to servers and access often affect several systems at once.

A certified IT security auditor (TÜV) works in the team. Access rights and security evidence are therefore considered together. Dependencies, access paths and affected applications are therefore reviewed together before a change. The agreed procedure includes a maintenance window, the functional test and a documented way back. Ongoing support keeps configurations and responsibilities current, so that later extensions stay traceable as well.

Secure remote access

Frequently asked questions

We are glad to answer your detailed questions in a personal conversation.

Is a particular identity service prescribed?

The choice depends on your infrastructure and the applications to be connected.

Can AI applications be connected as well?

Yes. Sign-in and permissions of AI systems can be connected to suitable identity services; we additionally define which content a role reaches.

How are privileged accounts handled?

We regulate service accounts and privileged accounts in the permission concept of your project.

First conversation

Arrange a free first conversation

Describe your task. We agree a date and discuss the possible project scope.

  1. Notebook on a desk with an open calendar and a selected appointmentAi

    1

    You request an appointment

  2. Joint planning of a segmented IT and OT infrastructure on a network diagramAi

    2

    We discuss your requirements

  3. Discussion of a security analysis with a network diagram and a list of measuresAi

    3

    You receive a quotation for the agreed scope

Philipp Niemann-Stryczek
Philipp Niemann-StryczekManaging DirectorLeads the company on the commercial side and answers questions on IT/OT security, asset administration shells, compliance and research projects.
Free first conversation

Describe your task in the contact form. We come back with a proposed date.

Arrange a first conversation

Not quite what you need?

Discover further suitable services.

Remote access

Limit external access to released systems, people and time windows.

Web applications

Combine dashboards, administration and business functions in one usable browser application.

AI-assisted knowledge management

Make released information usable via a connected AI knowledge base.