NEWFlows V2 has been releasedSee what shipped
INTEGRATIONSIDENTITY PROVIDER
KC
Keycloak28 OF 28 CAPABILITIES ASSESSED

Keycloak realm users, groups and roles, governed from Ploy

Realm users, groups and realm roles, with users created, disabled and removed, and group and role membership granted from Ploy.

TYPE · IDP
Keycloak connectorHOURLY SYNCCAPABILITIES
WHAT PLOY DOES
Sync realm usersEvery user in the connected realm arrives in Ploy as an identity, read from the complete user list on each scan. Service accounts arrive as non-human identities.
READ
Read disabled usersA user disabled in Keycloak is marked blocked in Ploy and their access to Keycloak is revoked on the same scan.
READ
Read authenticator app enrolmentWhether each user has enrolled an authenticator app for one-time codes.
READ
Map groups at every depthEvery realm group, nested groups included, lands as a resource named by its full path, with its direct members.
READ
Map realm roles and who holds themRealm roles land as resources with the users who hold each one directly.
READ
Create realm usersPloy creates an enabled user with the person's email and name, and can email them a link to set their password when the realm sends mail.
WRITE
Disable and re-enable usersPloy disables the user and signs them out of every live session, so the suspension takes effect at once. Re-enabling restores sign-in.
WRITE
Remove usersPloy deletes the user from the realm.
WRITE
Reset a passwordPloy sets a temporary password and sends it to the person. Keycloak makes them choose their own at the next sign-in.
WRITE
Grant and revoke group membershipPeople are added to and removed from a realm group from the group's own page in Ploy.
WRITE
Grant and revoke realm rolesPeople are given and relieved of a realm role from the role's own page in Ploy.
WRITE
2.1WHAT IT UNLOCKS

Three jobs this connector does on day one

ACCESS

An approved request becomes group membership

Ploy puts the person in the Keycloak group or realm role that carries the access, and takes them out again when the access ends.

LEAVERS

Disabled and signed out in one step

Ploy disables the realm user and ends their live sessions, so a leaver loses access now rather than when their token expires.

REVIEWS AND EVIDENCE

Who sits in which group, by full path

Every group is named by its place in the hierarchy, so a reviewer can tell two groups with the same name apart and see who holds each one.

2.3

SETUP

TYPICALLY 10 MINUTES
STEP 01

Create a confidential client

In the realm, create a client with Client authentication and Service accounts roles on. Give its service account the realm-management roles view-users and manage-users, and view-realm for realm roles.

STEP 02

Enter the connection details

Enter the Keycloak server URL, the realm name, and the client ID and secret. Ploy checks that the client can read the realm's users before it saves the connection.

STEP 03

Watch the first sync

Users, groups, realm roles and who holds each one land in the graph.

2.4OFTEN CONNECTED TOGETHER
OktaIDENTITY PROVIDERGitHubSOURCE CONTROLSlackAPPROVALS
BROWSE ALL 83 INTEGRATIONS

Connect Keycloak, see it in 10 minutes.