Keycloak as IDP and Azure AD as SP

%3CLINGO-SUB%20id%3D%22lingo-sub-2859873%22%20slang%3D%22en-US%22%3EKeycloak%20as%20IDP%20and%20Azure%20AD%20as%20SP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2859873%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20folks%2C%20I%20am%20trying%20to%20user%20Keycloak%20as%20the%20main%20Identity%20provider%20but%20I%20need%20to%20user%20azure%20AD%20for%20the%20underlying%20authentication%20since%20I%20am%20trying%20to%20authenticate%20powerbi.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20doesn't%20appear%20to%20me%20to%20be%20possible%20for%20powerBI%20to%20have%20an%20external%20Idps%20other%20than%20Azure%20AD%20so%20What%20I%20would%20like%20to%20achieve%20is%20to%20use%20Keycloak%20as%20IDP%20and%20maybe%20confirm%20identities%20trough%20SAML%20or%20OPENID%20connect.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethe%20main%20point%20is%20that%20the%20user%20hitting%20to%20the%20powerbi%20link%20gets%20redirected%20to%20keycloak%2C%20there%20upon%20authentication%2C%20keycloak%20would%20interface%20with%20Azure%20AD%20via%20SAML%20or%20OPENID%20to%20grant%20than%20the%20access%20to%20powerBI.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20that%20possible%20at%20all%3F%20Pretty%20much%20using%20keycloak%20to%20broker%20an%20identity%20to%20azure%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2859873%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2889185%22%20slang%3D%22en-US%22%3ERe%3A%20Keycloak%20as%20IDP%20and%20Azure%20AD%20as%20SP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2889185%22%20slang%3D%22en-US%22%3EEven%20I%20have%20a%20same%20line%20of%20requirement%20where%20I%20have%20existing%20users%20in%20Keycloak%20whom%20I%20need%20to%20give%20access%20to%20Azure.%20Keycloak%20will%20become%20IDP%20and%20Azure%20becomes%20SP.%20I%20am%20able%20to%20achieve%20this%20with%20AWS%20through%20SAML%20integration.%20Is%20there%20a%20way%20to%20do%20this%20with%20Azure%20as%20well.%3C%2FLINGO-BODY%3E
New Contributor

Hello folks, I am trying to user Keycloak as the main Identity provider but I need to user azure AD for the underlying authentication since I am trying to authenticate powerbi.

 

It doesn't appear to me to be possible for powerBI to have an external Idps other than Azure AD so What I would like to achieve is to use Keycloak as IDP and maybe confirm identities trough SAML or OPENID connect.

 

the main point is that the user hitting to the powerbi link gets redirected to keycloak, there upon authentication, keycloak would interface with Azure AD via SAML or OPENID to grant than the access to powerBI.

 

Is that possible at all? Pretty much using keycloak to broker an identity to azure?

1 Reply
Even I have a same line of requirement where I have existing users in Keycloak whom I need to give access to Azure. Keycloak will become IDP and Azure becomes SP. I am able to achieve this with AWS through SAML integration. Is there a way to do this with Azure as well.