SSO and identity management with Keycloak or Entra ID

We wire single sign-on across every app you run, through Keycloak or the Entra ID you already have: OIDC and SAML, groups mapped to roles, multi-factor authentication, and leavers who lose access the day they leave.

Start with one workloadBook a 30-minute briefing

Identity provider
Keycloak, or your existing Entra ID
Protocols
OIDC, SAML 2.0, LDAP federation
Access
Groups mapped to roles, MFA enforced
Pricing
On request, per estate

What the identity service covers

Every app with its own password list is an account someone forgets to close. The identity service puts one sign-in in front of all of them, driven by the directory you already trust.

Single sign-on across apps

Each app is connected over OIDC or SAML, so staff sign in once and every app trusts the same identity provider.

Keycloak or Entra ID

We operate Keycloak on your premises or in Pilae Cloud, or connect your apps to the Entra ID tenant you already run.

Your directory stays the source

Active Directory or LDAP is federated read-only into Keycloak, so accounts keep coming from where they already come from.

Groups mapped to roles

Directory groups decide who is an admin, an editor or a reader in each app. Change the group and the roles follow at the next sign-in.

Multi-factor authentication

One-time codes and security keys through WebAuthn, enforced per group, with stronger rules for administrators.

Joiners, movers and leavers

A new starter gets the right apps on day one. A move changes their roles. A leaver is disabled once and loses sign-in to every connected app at the same moment.

Single sign-on for open-source apps

A self-hosted estate often grows one login at a time: a local admin in the file server, another in the automation tool, a shared password for the dashboard. Each one is a place where a leaver keeps access. The identity service replaces them with one sign-in, run by an identity provider your security team controls.

We connect each app over OIDC or SAML, test it with real accounts and only then retire its local passwords. Nextcloud, Open WebUI, LibreChat, Outline and Grafana are common first connections. Where an app reserves single sign-on for a paid edition, we tell you before you choose it.

Keycloak, Entra ID, or both

If you run Microsoft 365, you likely have Entra ID already, and connecting your apps to it keeps one directory and one set of policies. If you want the identity provider on your own machines, Keycloak runs on your premises or in Pilae Cloud, federates Active Directory or LDAP read-only, and can broker Entra ID sign-ins for organisations moving away from Microsoft gradually. Weighing it against a hosted provider? See the Okta alternative.

Joiners, movers and leavers that follow the directory

Roles come from groups. When HR adds a starter to a department group, the right apps open to them. When someone changes team, their group changes and so do their roles. When they leave, disabling one account ends sign-in to every connected app. Sign-in and admin events go to the audit log in the control plane and on to your SIEM.

Identity is also the front door of the private network: staff reach apps on the mesh only after they sign in. Read more on how we secure your apps, or contact us to scope single sign-on for your estate.

How an identity project runs

  1. Map

    We list every app, how it signs users in today, which protocols it supports and which groups should grant which roles.

  2. Design

    Realm or tenant layout, group model, MFA policy, session lifetimes and the break-glass accounts, agreed in writing.

  3. Connect

    Each app is switched to single sign-on in turn, tested with real accounts before its local passwords are retired.

  4. Enforce

    MFA is switched on per group, local admin accounts are locked away, and sign-in events flow to the audit log.

  5. Hand over

    Your identity team receives the design, the runbook for joiners, movers and leavers, and a session on day-to-day administration.

What your contract includes

Apps in scope
Every app to be connected is listed, with the protocol and role mapping for each one.
Identity provider
Keycloak operated by Pilae with patching, backups and monitoring, or configuration of your own Entra ID tenant.
MFA policy
Written per group and enforced at the identity provider, with the recovery procedure documented.
Leaver process
Disabling an account in your directory ends sign-in to every connected app. The runbook states how existing sessions are ended.
Audit
Sign-in and administration events retained and exportable to your SIEM.
Break-glass access
Emergency accounts defined, stored and tested, so an identity outage does not lock you out of your own apps.

The apps behind it

Questions

Should we use Keycloak or Entra ID for single sign-on?

If your organisation already runs Entra ID and is content to keep it, we connect your apps to it. If you want an identity provider that runs on your own infrastructure, or you need to federate several directories, Keycloak is the usual choice. The two can also work together, with Keycloak brokering Entra ID sign-ins.

Which protocols do you support?

OIDC and SAML 2.0 for applications, and LDAP or Active Directory federation for the directory. Keycloak handles OIDC and SAML clients in the same realm, so older SAML-only systems and newer OIDC apps sit side by side.

Do all open-source apps support single sign-on?

Most do, over OIDC or SAML. A few reserve single sign-on for a paid edition. The mapping step names each one and its licence terms before anything is connected, so there are no surprises later.

What happens when someone leaves?

You disable the account in your directory, as you do today. Because every connected app signs in through the identity provider, that one change ends access to all of them. The runbook covers ending sessions that are already open.

Is Keycloak open source?

Yes. Keycloak is released under the Apache-2.0 licence and is an incubating project of the Cloud Native Computing Foundation. Pilae operates it for you, including upgrades tested before they reach production.

Can multi-factor authentication be enforced only for some users?

Yes. MFA policy is set per group. A common setup requires security keys for administrators and one-time codes for everyone else, with exceptions documented and reviewed.

Related

Put one sign-in in front of every app.

Send us the list of apps your teams sign into. We come back with a protocol map, a group model and a quote.