---
title: Configure an Active Directory as a User Federation in Keycloak
slug: edgemanager/quickstart-guide/configure-active-directory-keycloak
description: You can connect an Active Directory to Keycloak through LDAP (Lightweight Directory Access Protocol) as a User Federation. 
docTags: 
createdAt: 2023-08-16T13:00:24.932Z
---

You can connect an Active Directory to Keycloak through LDAP (Lightweight Directory Access Protocol) as a User Federation.&#x20;

# Before You Begin

You will need an Active Directory to connect to. If needed, follow up with your IT department to create one.&#x20;

# Step 1: Configure Standalone Realm

You will first need to configure the default standalone realm with the new LDAP provider that you will create. &#x20;

**To configure the standalone realm:**

1. Log in to Keycloak using the following URL: **https\://\[LEM IP address]/auth/admin**. See [Access Keycloak](docId\:w3uHZQ4tSrH7OLjhuLt0A) to learn more.&#x20;
2. In the top-left corner, open the drop-down list for the master realm and select **standalone**.
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/y2t0GoD8v_UcbeqpaocPS_standalone.png" size="80" width="1920" height="728" position="center" caption="Standalone realm" showCaption="true"}
3. In the left-navigation menu, selec&#x74;**&#x20;User Federation** and click **Add Ldap providers**.
   The *Add LDAP provider&#x20;*&#x70;age displays.&#x20;
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/KZ5eK-n1Py6rJv7WZd2nh_standalone-ldap-provider.png" size="80" width="1920" height="725" position="center" caption="Add Ldap providers option" showCaption="true"}
4. In the *General options* section, enter a display name for the provider and select **Active  Directory** as the vendor.&#x20;
   After selecting the vendor, the following fields are auto-filled:
   **Username LDAP attribute**
   **RDN LDAP attribute**
   **UUID LDAP attribute**
   **User Object classes**
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/Y8iKFAtIGuw4eO3SGPwsr_general-options.png "General options section")
5. In the *Connection and authentication settings* section, you will need to configure the external AD LDAP server. Enter the following URL: **ldap\://\[AD server IP address]**. Configure the other connection parameters as required. Then, click **Test connection&#x20;**&#x74;o confirm the LDAP connection is successful.&#x20;
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/7G7bt1vBx3BKlUpTqprTO_connection-url.png "Connection and authentication settings section")
6. Configure the following settings and click **Test authentication** to confirm they are correct.&#x20;
   **Bind type**: Select the type of the authentication method used during the LDAP bind operation: **none&#x20;**(anonymous LDAP authentication) or **simple&#x20;**(bind credential + bind password authentication).
   **Bind DN**: Enter the DN of the LDAP admin.
   **Bind credentials**: Enter the password of the LDAP admin.&#x20;
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/OcjrwrIYytFlWF7lYhUal_bind-settings.png "Bind settings")
7. In th&#x65;*&#x20;LDAP searching and updating* section, configure the **User LDAP filter** field with appropriate LDAP filters. This allows you to restrict users and enhance security and performance. &#x20;
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/UL_V0NfOD6G1dmSf0z5yN_user-ldap-filter.png" size="80" width="1089" height="719" position="center" caption="LDAP searching and updating section" showCaption="true"}
8. Configure the remaining settings as needed and then click **Save**.&#x20;

# Step 2: Confirm Successful Setup

After creating the realm, you can test the connection to confirm the Active Directory is successfully set up.&#x20;

**To confirm the setup is successful:&#x20;**

1. In the left navigation menu, select **Clients**. Then, click the home URL for **account-console**.&#x20;
   The Keycloak account management page opens in a new browser tab.&#x20;
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/8_LBPJokMywFqP-1_sd1U_account-console.png "Clients page")
2. Click **Sign out&#x20;**&#x61;nd then click **Sign in**.&#x20;
   The Keycloak sign in page displays.&#x20;
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/IEMxkcXu_16fG9ew3im03_sign-out.png "Sign out button")
3. Use the credentials of any user in your Active Directory to sign in.&#x20;
   If the login in successful, the user is now authenticated using an Active Directory.&#x20;
4. Log in again to Keycloak, select **Users**, and confirm that the user you just logged in with is listed.&#x20;
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/EHtQUtWUys2NEgEderDPB_users.png "Users section")

