Keycloak SSO/Kerberos with IIS

612 views
Skip to first unread message

Jernej Vodopivec

unread,
Nov 15, 2021, 7:43:26 AM11/15/21
to Keycloak User
Hi, I would kindly ask for some hint how Kerberos / SSO could be implemented for the following scenario (Microsoft AD environment):
- nginx as a reverse proxy server - frontend
- Keycloak as a Form based (pre)authentication - users are synced from AD
- delegation of user credentials to backend IIS server (OWA, SharePoint) to achieve seamless SSO user authentication
Thank you very much for any valuable information!
Regards,
Jernej

Evan Schnell

unread,
Nov 16, 2021, 8:48:50 AM11/16/21
to Keycloak User
I'm chasing down a question that's tangential to this.  Can you just use the "Microsoft" identity provider?    How common is "Microsoft" authentication at customers using AD?  Looking ahead when deploying keycloak should we ignore Kerberos and focus on the "Microsoft" identity provider?    In your case can you use the "Microsoft" identity provider at your enterprise?  If not why not?  What differentiates AD customers from Microsoft login customers?  
Reply all
Reply to author
Forward
0 new messages