Configure External IAM Security Groups (Optional)#

If a connection is made between Keycloak solution and an external IAM, you can manage groups in Keycloak solution or in the external IAM.

See Configuring Users and Groups in Keycloak IdP for additional information on configuring users and groups in Keycloak solution.

Note

This setup is optional and not required for use with Keycloak solution.

Supported User Groups#

See Configuring Users and Groups in Keycloak IdP for additional information on Edge Orchestrator Groups and Roles for a list of Edge Orchestrator groups.

Assign Users to Groups in Microsoft Azure* AD#

To create security groups in Azure AD, see Learn about groups and access rights in Microsoft Entra ID.

Assign Users and Groups#

  1. In the Azure Enterprise Application, open the Users and groups section.

  2. Add any Azure AD users or groups as necessary.

Map Users and Groups in Keycloak Solution#

  1. Navigate to the Keycloak page.

  2. Select Identity providers from the left navigation bar.

  3. Select the identity provider corresponding to the Azure AD provider

  4. Go to the Mappers tab,

  5. Select Add Mapper to create a mapper for each Azure AD security group to map them to the corresponding Keycloak group.

For more information about mappers in Keycloak solution, see Mapping claims and assertions. Azure AD can now populate the new users and groups in Keycloak solution.

Add Users to Groups from an External IAM#

To create groups and assign users to them in your IAM, see the IAM documentation regarding groups. To integrate another IdP with Keycloak solution, see Integrating identity providers.