In 2026, identity is the core security layer. If it fails, everything fails. Yet many mid-sized firms still run six to eight separate logins: AD for Windows clients, a cloud login for Microsoft 365, and one more account each for the ERP, the wiki and the VPN. SecTepe.Comm sets up one central identity layer with Keycloak. A lightweight AD connector links in hybrid setups, so you don't have to migrate.
Why SSO, and Why Keycloak?
SSO brings three clear gains:
- Fewer passwords, so there is less to phish.
- Central offboarding: you disable a user once, and they are locked out everywhere.
- One audit trail.
Keycloak has been the open-source standard for this for years. It offers OIDC, SAML 2.0, optional FIDO2/WebAuthn, strong MFA options, brute-force protection and fine-grained role mapping.
What Makes the SecTepe.Comm Setup Different
- Realms set up for you: on deployment, Keycloak clients for Mailcow, RocketChat, BookStack, GitLab, Grafana and others are created on their own. Group and role mapping is included.
- SSO bridges for non-OIDC apps: some tools only speak LDAP or header auth. They get a bridge container that turns OIDC tokens into the auth model the tool needs.
- CTI IP check at login: before login, Keycloak asks the built-in CTI stack if the source IP is on a block list. Phishing logins from known C2 IPs are turned away at once.
- Self-service recovery: users reset passwords and recover MFA in the Keycloak account console. No helpdesk ticket needed.
The AD Connector: A Bridge, Not a Big Bang
Most mid-sized firms have an AD forest that works, and no plan to migrate it. The SecTepe.Comm AD connector is an on-prem sidecar. It does four things:
- It syncs user lists, groups and status (active or disabled) in both directions.
- It turns on Kerberos SSO for domain-joined clients. Users log in once and never type their password into the browser.
- It maps AD groups to Keycloak roles on its own, for example "Domain Admins" → "mail-security-admin".
- When you disable a user in AD, it turns that user off in Keycloak within 30 s. That also locks them out of every linked app.
MFA: Sensible, Not Annoying
A good MFA plan keeps protection out of sight and the risk of failure low:
- FIDO2 hardware keys (such as YubiKey) for admins, operators and privileged roles. This is mandatory.
- TOTP (Authy, Google Authenticator) for regular users. This is the default.
- Push messages via a mobile app for "convenience" logins. Each user can opt in.
- Backup codes that users can print on their own.
- A social-engineering-resistant WebAuthn flow also helps awareness training. The "read me the code on your phone" trick no longer works.
Avoiding Vendor Lock-In
Microsoft Entra ID is powerful. It is also expensive once you use the good features, like conditional access and privileged identity management. And it puts your identity data in the Microsoft cloud. With NIS-2 and the Schrems II debate, that is more and more in question. A Keycloak stack follows open standards, so a later move stays possible. At the same time, it is sovereign enough that you are never forced to move.
Day-to-Day Operation
A Keycloak instance with 5,000 users and 30 apps runs fine on a VM with 4 vCPUs and 8 GB RAM. Hosting costs less than €50 a month. The license is Apache 2.0. For support, you can use commercial partners (SecTepe is one) or run it yourself with help from the active community.
Conclusion
Identity is the security layer where spending pays off most. No mail filter, sandbox or SIEM can make up for user accounts nobody keeps track of. Keycloak plus the AD connector is a practical answer that is vendor-neutral and EU-sovereign. A clean first setup takes two to four weeks with expert help. After that, you can add each new app in hours, not weeks.