I created a SAML Identity Provider in Keycloak. The single signon url is https://[URL]/adfs/ls as stated in the FederationMetadata.xml.
If I am now using the Keycloak-User-Login I see a link, where I'll be redirected to the single signon page, but after that I get an error, because I didn't specify any query parameter like wa=signin1.0 or whr=https:\\foo\adfs\services\trust or wtrealm=https:\\sso.foo.bar
If I am including this parameters into the signle signon url correctly, I can login, but keycloak doesn't recognise what happened.
As it seems to me the URL confgured as single signon url does nothing and the Identity Provider as I have configured it in Keycloak is useless.
Can anyone help me with some pointers, to increase my understanding of the interaction between AD FS and keycloak and how they work together?