This post describes the setup and configuration of an OpenID Connect (OIDC) Identity provider in Keycloak for federation with Microsoft Entra ID.
Keycloak version: 26.7.3
Goals
- Allow users of a specific Entra ID tenant to sign in to Keycloak using their Entra ID account
- Restrict sign in / access to member users of the specified Entra ID tenant
Concept

Step-by-Step Instructions
NOTE
The optional claim acct (see Optional claims reference) is configured to pass the users account status to Keycloak (if the user is a Member of the Entra ID tenant or a Guest). The identity provider in Keycloak for federation with Entra ID is then configured to require the acct claim to be 0 (0 = Member of the Entra ID tenant, 1 = Guest) for successful authentication (see essential claim configuration below).
- Log in to the Azure Portal
- Search for
App registrationsin the search bar on the top and select it from the results - Create a new app registration by clicking on
New registration - Log in to the Keycloak admin console with an account that has administrative privileges (at least for the corresponding realm)
- Ensure the current realm is set correctly before proceeding
- Navigate to the
Identity providerssection in the menu on the left-hand side - Click on the
Add providerbutton and selectOpenID Connect v1.0from the list of available providers
- Configure the OpenID Connect provider as follows
Alias: specify the unique identifier for the identity provider (i.e.entra-oidc)
Display name: Entra ID
Use discovery endpoint:On
Discovery endpoint:https://login.microsoftonline.com/ENTRA_ID_TENANT_ID_HERE/v2.0/.well-known/openid-configuration
Validate Signatures:On
Use JWKS URL:On
Client authentication:JWT signed with private key
Client ID:CLIENT_ID (Application (client) ID of the app registration in Entra ID created above)
Client assertion signature algorithm:RS256
Add X.509 Headers to the JWT:On - Click
Add - Update the identity provider
Settingsas follows
Use PKCE:On
PKCE Method:S256
Pass login_hint:On(optional)
Pass current locale:On(optional)
Send ‘id_token_hint’ in logout requests:On
Send ‘client_id’ in logout requests:On
Disable user info:On
Scopes:openid profile email(adjust according to your needs)
Trust Email:On(optional)
Verify essential claim:On
Essential claim:acct
Essential claim value:0
Sync mode:Force
Case-sensitive username:On
Supports client assertions:On - Click
Save - Navigate to the
Mapperstab - Add mappers if needed
- Navigate to
Realm settingssection in the menu on the left-hand side - Navigate to the
Keystab - Click on the
Certificatebutton on the key with algorithmRS256 - Create
.pemfile from the public key part of the downloaded certificate (manually) - Log in to the Azure Portal
- Search for
App registrationsin the search bar on the top and select it from the results - Open the before created app registration
- Navigate to the
Certificates & secretstab - Switch to the
Certificatestab - Click on the
Upload certificatebutton and select the.pemfile created from the Keycloak public key - Set description (i.e.
Keycloak realm (REALM_NAME) certificate) - Click
Add - Navigate to
Authentication (Preview) - Click on the
Add Redirect URIbutton - Select
Web - Enter the redirect URI value from the Keycloak identity provider settings
- Click
Save - Navigate to
Token configuration - Click on the
Add optional claimbutton - Select
ID - Select the
acctclaim - Click
Add - Click on the
Add optional claimbutton again - Select
Access - Select the
acctclaim - Click
Add - Navigate to
API permissions - Ensure Microsoft Graph
User.Readpermission of typeDelegatedis added and granted for the current tenant
That’s it.


Leave a Reply