You are on page 1of 4

KeyCloak –

Restrict Access to
Group
Create Client
• In an existing realm, creat a new client (Open ID Connect or SAML)
• Important: Activate option „Authorization Enabled“
Restrict Access to Group
• You already have a set of default „access-all“ settings
inside new tab „Authorization“.
• Add your restriction
Check / Evaluate Restriction
• In register „Authorization / Evaluate“, first select User to check
• Important: Select a combination of resource (and optional scope) -
and press „Add“ Button
• Your selection will be added to list
• Then you can check if your condition is met

You might also like