Hardcoded Ldap Group will not sync to Ldap

27 views
Skip to first unread message

Emma Richardson

unread,
May 5, 2021, 4:23:37 PM5/5/21
to Keycloak User
I have an MSAD federated instance to Keycloak.  It is working very well.  I added the group mapper and then also added a hard coded group to add to all new members of this federated instance.  

What I want to happen:
I created this instance for new registrations.  I want each new registration to be automatically added an MSAD group.  (I cannot just set this as a default group because I only want this federated instance (one of three) to be added to it.)

What works:
I can add a group to user in keycloak and it syncs to MSAD.
I can remove a group in keycloak and it syncs to MSAD.
I can register a new user through this connection, it adds the user to the hard coded group in Keycloak and creates the new user.  The new user shows up as expected in MSAD.

What does not work:
I cannot get the hard-coded group to sync back to MSAD.  It is a group that was initially imported from MSAD but when it is referenced as the hardcoded group, it just will not sync back.  So the new user, while a member of the group in Keycloak, is not a member of the group in MSAD.

Any suggestions?


Reply all
Reply to author
Forward
0 new messages