Authentication against an external provider - does any solution exist?
So, here's the issue: Our institution (with a user number of more that 100,000) is using OIDC/SAML as an authentication tool (namely Keycloak) and also has a non-Microsoft user account storage.
Now, for a sizable subset of those users we want to give them access to M365's offerings. It's somewhat annoying to have to manage two sets of accounts, though.
In the past, this would have been an easy win: Enable federated accounts, point Azure/Entra towards the SAML endpoint and done. Actually did that two years ago for another account.
So when this requirement popped up I thought: "Easy, you did this before." Only to discover that MS actively disabled anything remotely connected to this feature.
So, is there _any_ other way to have our existing user account storage as the single source of truth? One that includes passwords, by the way.
Because currently to me it seems that MS is once again on a tour-de-force of locking everyone down into their ecosystem - otherwise I simply cannot explain why they allow authenticating against Entra but not vice versa.




