Objective
I'm would like to create a Keycloak role similar to manage-users which has only the ability to create users in a specific realm.
Current Progress
I've setup my realm testRealm
I've setup my client testClientA inside testRealm
with Service Account Enabled
and grant_type = client_credentials
I've added the manage-users role to Service Account Roles to enable the request from my client application to create a new user. (Working fine)
Problem
The problem i'm faced with is the manage-users role is far too broad and if the testClientA service account is ever compromised, the (attacker / bad actor) has full access to the users in the realm along with group administration.
Additional Background
Keycloak version = 15.0.2
Running in PreviewMode with admin_fine_grained_authz enabled
Note:
I've been looking into fine-grain admin permissions to see whether something here might fit my use-case but haven't managed to get anything working successfully. I'm fairly new to Keycloak so would be grateful for as much guidance as possible and welcome alternative approaches to solving this problem.