Configure LDAP / Active Directory Federation

This guide walks through setting up LDAP or Microsoft Active Directory user federation in Keycloak, enabling users from your corporate directory to authenticate without migrating credentials.

For background concepts, see Identity Federation.

Prerequisites

  • A running Keycloak instance with admin access.
  • Network connectivity from Keycloak Pods to the LDAP/AD server.
  • An LDAP bind account with read access to the user directory (and write access if using WRITABLE edit mode).
  • The LDAP base DN and user search filter for your directory structure.

Step 1: Add the LDAP Provider

  1. In the Admin Console, select the target Realm.
  2. Go to User federation in the left navigation bar.
  3. Click Add LDAP provider.
  4. Configure the connection settings:
FieldDescriptionExample
Console Display NameA friendly name for this providerCorporate AD
VendorThe directory vendor. Optimizes default settings.Active Directory, Red Hat Directory Server, Other
Connection URLLDAP server URLldaps://ldap.example.com:636
Enable StartTLSUse StartTLS for LDAP connections on port 389Off (use ldaps:// instead)
Bind Typesimple for username/password bindsimple
Bind DNThe DN of the service account used by Keycloakcn=keycloak-svc,ou=ServiceAccounts,dc=example,dc=com
Bind CredentialThe password for the bind DN(enter the password)
  1. Click Test connection to verify connectivity.
  2. Click Test authentication to verify bind credentials.
FieldDescriptionExample
Edit ModeHow Keycloak interacts with LDAP — see the table belowREAD_ONLY
Users DNThe base DN for user searchesou=Users,dc=example,dc=com
Username LDAP attributeThe LDAP attribute mapped to Keycloak usernamesAMAccountName (AD) or uid (LDAP)
RDN LDAP attributeThe LDAP attribute used as the RDNcn
UUID LDAP attributeThe LDAP attribute used as the unique IDobjectGUID (AD) or entryUUID (LDAP)
User Object ClassesLDAP objectClass filter for usersperson, organizationalPerson, user (AD)
Search ScopeOne Level or Subtree (includes nested OUs)Subtree
Custom User LDAP FilterAdditional LDAP filter to narrow results(memberOf=cn=AppUsers,ou=Groups,dc=example,dc=com)

Edit Modes

ModeDescriptionUse Case
READ_ONLYKeycloak reads from LDAP but never writes back. Password changes go through LDAP directly.When Keycloak should not modify the directory
WRITABLEKeycloak can update user attributes and passwords in LDAP.When Keycloak manages the full user lifecycle
UNSYNCEDKeycloak stores changes locally without writing to LDAP.Temporary overrides or testing

Step 3: Configure Synchronization

Synchronization imports user data from LDAP into Keycloak's local cache for faster lookups.

SettingDescriptionRecommended
Import UsersWhether to import LDAP users into Keycloak's local databaseOn
Periodic Full SyncEnable scheduled full synchronizationOn
Full Sync PeriodInterval in seconds for full sync86400 (daily)
Periodic Changed Users SyncEnable incremental sync of recently modified usersOn
Changed Users Sync PeriodInterval in seconds for changed-user sync3600 (hourly)

Click Save, then click Synchronize all users to perform the initial import.

Verify the import by going to Users and searching for LDAP users.

Step 4: Configure LDAP Mappers

LDAP Mappers define how LDAP attributes are mapped to Keycloak user attributes, groups, and roles.

Default Mappers

When the LDAP provider is created, Keycloak auto-creates several default mappers. Review them in the Mappers tab:

MapperTypeDescription
usernameuser-attribute-ldap-mapperMaps sAMAccountName (or uid) to Keycloak username
emailuser-attribute-ldap-mapperMaps mail to Keycloak email
first nameuser-attribute-ldap-mapperMaps givenName to Keycloak firstName
last nameuser-attribute-ldap-mapperMaps sn to Keycloak lastName

Add a Group Mapper

To synchronize LDAP groups to Keycloak groups:

  1. In the LDAP provider detail, click the Mappers tab.
  2. Click Add mapper.
  3. Select group-ldap-mapper.
  4. Configure:
FieldDescriptionExample
LDAP Groups DNBase DN for group searchesou=Groups,dc=example,dc=com
Group Name LDAP AttributeLDAP attribute for group namecn
Group Object ClassesLDAP objectClass for groupsgroupOfNames or group (AD)
Membership LDAP AttributeLDAP attribute listing group membersmember
Membership Attribute TypeDN or UIDDN
Drop non-existing groups during syncRemove Keycloak groups not found in LDAPOff (recommended for safety)
  1. Click Save, then click Sync LDAP groups to Keycloak.

Add a Role Mapper

To map LDAP groups directly to Keycloak Realm roles:

  1. Click Add mapper > role-ldap-mapper.
  2. Configure the LDAP roles DN, role object classes, and membership attributes (similar to group mapper).
  3. Set Use Realm Roles Mapping to On.
  4. Click Save and sync.

Step 5: Configure LDAP over TLS

For production environments, always use encrypted LDAP connections.

Use ldaps:// in the Connection URL (port 636):

ldaps://ldap.example.com:636

If the LDAP server uses a certificate signed by a custom CA, import the CA certificate into the Keycloak truststore. In a Kubernetes-managed deployment, mount the CA certificate and configure the JVM truststore via the Keycloak CR:

spec:
  additionalOptions:
    - name: spi-truststore-file-file
      value: /opt/keycloak/certs/truststore.jks
    - name: spi-truststore-file-password
      secret:
        name: keycloak-truststore-secret
        key: password
  unsupported:
    podTemplate:
      spec:
        containers:
          - volumeMounts:
              - name: truststore
                mountPath: /opt/keycloak/certs
        volumes:
          - name: truststore
            secret:
              secretName: keycloak-truststore
Truststore Configuration

The exact mechanism for configuring custom truststores may vary between Keycloak versions. Verify the truststore SPI configuration options in the upstream Keycloak documentation for your specific version before applying this configuration.

Option B: StartTLS

Use ldap:// with StartTLS enabled (port 389):

ldap://ldap.example.com:389

Enable StartTLS in the LDAP provider configuration. The same CA certificate truststore configuration applies.

Troubleshooting

SymptomPossible CauseResolution
Connection test failsNetwork policy blocking LDAP port, incorrect URLVerify Pod-to-LDAP connectivity with kubectl exec and test with ldapsearch
Authentication test failsIncorrect Bind DN or credentialsVerify the Bind DN format matches your directory structure
No users found after syncIncorrect Users DN or User Object ClassesCheck the Users DN matches the actual LDAP tree. Use Subtree search scope for nested OUs.
Users visible but cannot log inEdit Mode set to UNSYNCED without local passwordsSet Edit Mode to READ_ONLY for LDAP-authenticated logins
Group sync returns emptyIncorrect Group Object Classes or Membership AttributeVerify objectClass and membership attribute names match your directory schema (groupOfNames vs group)
SSL/TLS handshake failureMissing CA certificate in truststoreImport the LDAP server's CA certificate into the Keycloak JVM truststore