Authentication
Authentication
Apporto NextGen supports several ways to authenticate users into your tenant. This section explains how authentication works and how to configure it.
Users can be authenticated through:
Local accounts — an email address and password managed directly in Apporto.
LDAP / Active Directory — your on-premises directory.
Single sign-on (SSO) — an external identity provider (such as Microsoft Entra ID or a SAML provider), brokered through an industry-standard Keycloak server that Apporto runs and maintains on your behalf.
In this section
Single Sign-On (SSO) with Keycloak — what Keycloak is, how the SSO sign-in experience works, and how to configure identity providers, roles, and group syncing.
More authentication topics will be added here over time.