Creating AAD Keycloak composite roles (optional post deployment step)
You can create composite roles in Keycloak and link them to Azure Active Directory groups. This may make the identity provider configuration in Keycloak simpler.
Pre-requisites
In order to successfully create composite roles in Keycloak you will need the following:
The Keycloak admin password and URLs of your kdb Insights Enterprise deployment.
Create composite roles
Follow the steps below to log in to Keycloak, which kdb Insights Enterprise uses as its Identity and Access Management component and create the necessary roles.
-
Use the
keycloakUrl
or theinsightsUiUrl
+/auth/
from section above to navigate to the Keycloak web UI. -
Click on
Administration Console
and log in with the usernameuser
and the password you provided during the deployment. -
Click on
Roles
in the left-hand menu then click on theAdd Role
button. -
Enter the Role Name:
<role name>
and clickSave
. -
Turn Composite Roles
ON
. -
Associate it with the desired roles