<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 12pt;
font-family:Calibri
}
--></style></head>
<body class='hmmessage'><div dir='ltr'>Hello,<div><br></div><div>The latest release notes talk about multi tenant enhancements like supporting multiple realms for a single application. Is it possible for a realm to delegate the authentication to a external identity provider like Ping or Okta (using SAML or OpenID Connect) providing some kind of identity federation. </div><div><br></div><div>One of the requirements for our app is that one or more of out tenants can use their own AD directory for authenticating users into our service. Eventhough keycloak has support for LDAP/AD, I'm not sure if customers will open up their directory for direct connectivity from our cloud service into their on premise AD. </div><div><br></div><div>Thanks,</div><div><br></div>                                            </div></body>
</html>