I have posted a question few weeks ago on similar topic - how to
retrieve Azure AD groups and roles, but nobody has answered.
So maybe you can tell me how you have your AD configured that you get
groups info in the token.
I have created OpenId identity provider with Azure Active directory and it
works. What I am failing is to retrieve any group or role information from
Azure, so I can assign corresponding roles in Keycloak.
In their documentation,
us/azure/active-directory/develop/active-directory-token-and-claims I see
that if response_type is specified as "id_token" additional claims
and "groups" should be returned.
But Keycloak's redirect to authorization URL in Azure contains parameter
response_type=code and there is no way to overwrite it.
Azure AD's openId configuration
id_token","token id_token","token"] but in
"claims_supported" don't mention
"groups" nor "roles" claims.
So question - is it possible to change response_type to include id_token,
so groups or roles claims are retrieved and can be used in mapper to assign
corresponding roles in Keycloak. If not - what is a suggested approach -
store the token and retrieve them separately?
Hi all,
I have the following configuration :
*My application :*
Front : Angular 2
Backend : Springboot rest api
Keycloak 3.0.0
Windows Azure AD
The goal is to use Keyloack and Windows Azure for authentication and
permissions management of my web app.
(I followed this tutorial :
*Windows Azure AD* : I registered my webapp into Azure AD
*Keycloak *: I added two clients (front & back) + an identity provider
The authentication part works well. (Each request is redirected to the
Microsoft auth, then a user in Keycloak is added (first login).
Now I would like to use information of the token of Azure (doc :
for permissions management.
A token from azure ad looks like below :
typ: "JWT",
alg: "RS256",
x5t: "kriMPdmBvx68skT8-mPAB3BseeA"
aud: "https://contoso.onmicrosoft.com/scratchservice",
iss: "https://sts.windows.net/b9411234-09af-49c2-b0c3-653adc1f376e/",
iat: 1416968588,
nbf: 1416968588,
exp: 1416972488,
ver: "1.0",
tid: "b9411234-09af-49c2-b0c3-653adc1f376e",
amr: [
roles: [
oid: "6526e123-0ff9-4fec-ae64-a8d5a77cf287",
upn: "sample.user(a)contoso.onmicrosoft.com",
unique_name: "sample.user(a)contoso.onmicrosoft.com",
sub: "yf8C5e_VRkR1egGxJSDt5_olDFay6L5ilBA81hZhQEI",
family_name: "User",
given_name: "Sample",
*groups: [
appid: "b075ddef-0efa-123b-997b-de1337c29185",
appidacr: "1",
scp: "user_impersonation",
acr: "1"