It is not currently possible in Keycloak to do Identity Brokering without having the external user either created/imported into the RH-SSO/Keycloak DB right after the broker authentication, or that an account representing the external exists before the broker authentication and in which case the broker account is linked to this existing user account.
The setup when there is no user account created/existing at all is not supported right now.
- is related to
-
RHBK-869 Transient users as an option to not import users from identity brokers
- New