[keycloak-user] Unable to Store and Retrieve Group-Role relationship in LDAP

abhishek raghav abhi.raghav007 at gmail.com
Fri Mar 10 05:31:01 EST 2017


Hi

I have a set of* Realm Roles* that is mapped to an certain *OU=Roles* in an
*MSAD*. Similar is the case for a set of *Groups*.

But when I *assign a group with a certain role, the assignment is visible
in Keycloak. But the same is not reflected on the AD.*
I mean, this mapping of role and group is *not stored in the "member" or
"memberof" attributes of either the respective group or the role*.

Please suggest is this functionality available using any mapper from
Keycloak to AD? Or do we need to create our own Custom Mapper? If yes, how?


*- Best Regards*
   Abhishek Raghav


More information about the keycloak-user mailing list