Keycloak restrict manage-users role for client to only allow create-user privileges

Viewed 579

Objective

I'm would like to create a Keycloak role similar to manage-users which has only the ability to create users in a specific realm.

Current Progress

I've setup my realm testRealm

I've setup my client testClientA inside testRealm with Service Account Enabled and grant_type = client_credentials

I've added the manage-users role to Service Account Roles to enable the request from my client application to create a new user. (Working fine)

Problem

The problem i'm faced with is the manage-users role is far too broad and if the testClientA service account is ever compromised, the (attacker / bad actor) has full access to the users in the realm along with group administration.

Additional Background

Keycloak version = 15.0.2
Running in PreviewMode with admin_fine_grained_authz enabled

Note:

I've been looking into fine-grain admin permissions to see whether something here might fit my use-case but haven't managed to get anything working successfully. I'm fairly new to Keycloak so would be grateful for as much guidance as possible and welcome alternative approaches to solving this problem.

0 Answers
Related