Authentication

Authentication

Authentication

Apporto NextGen supports several ways to authenticate users into your tenant. This section explains how authentication works and how to configure it.

Users can be authenticated through:

  • Local accounts — an email address and password managed directly in Apporto.

  • LDAP / Active Directory — your on-premises directory.

  • Single sign-on (SSO) — an external identity provider (such as Microsoft Entra ID or a SAML provider), brokered through an industry-standard Keycloak server that Apporto runs and maintains on your behalf.

In this section

  • Single Sign-On (SSO) with Keycloak — what Keycloak is, how the SSO sign-in experience works, and how to configure identity providers, roles, and group syncing.

More authentication topics will be added here over time.