# \[Decision Strategy\] Affirmative strategy doesn't behave as expected

**URL:** <https://forum.keycloak.org/t/decision-strategy-affirmative-strategy-doesnt-behave-as-expected/12010>\
**Category:** Configuring the server\
**Created:** [November 10, 2021, 3:44pm UTC](https://forum.keycloak.org/t/decision-strategy-affirmative-strategy-doesnt-behave-as-expected/12010 "2021-11-10T15:44:45Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![davidep](https://avatars.discourse-cdn.com/v4/letter/d/71c47a/32.png) [@davidep](https://forum.keycloak.org/u/davidep)\
**Post date:** [November 10, 2021, 3:44pm UTC](https://forum.keycloak.org/t/decision-strategy-affirmative-strategy-doesnt-behave-as-expected/12010/1 "2021-11-10T15:44:45Z")

</div>

Hi everybody,  
I’m setting up keycloack (version 15.0.2) for securing REST API in a microservices environment and looks like there is either a problem in the documentation or I am missing something, so looking for help.

The problematic setup seems quite straightforward, I have a client that acts as the resource server in which I’ve defined a resource, let’s call it “Resource-A” and this resource has 2 resource-permission registred: “Permission-A” and “Permission-B”.

For “Permission-A” a client policy is defined and for “Permission-B” there is a role policy.

Now, having setted the resource server decision strategy to “affirmative”, as for documentation  
“_As an example, if two permissions for a same resource or scope are in conflict (one of them is granting access and the other is denying access), the permission to the resource or scope will be granted if the choosen strategy is `Affirmative` . Otherwise, a single deny from any permission will also deny access to the resource or scope._” I think that the access should be granted when one of the two permission is evaluated to permit but that’s not what heappening, and I always end up with a deny.

I found this previous topic but looks like nobody answered to it  
[https://www.keycloak.org/docs/latest/authorization\_services/](https://www.keycloak.org/docs/latest/authorization_services/)

Thanks in advance,  
greetings.

---

<div class="post-metadata">

**Author:** ![lense](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/lense/32/3274_2.png) [@lense](https://forum.keycloak.org/u/lense)\
**Post date:** [November 22, 2021, 7:24am UTC](https://forum.keycloak.org/t/decision-strategy-affirmative-strategy-doesnt-behave-as-expected/12010/2 "2021-11-22T07:24:11Z")

</div>

+1.  
I got the same problem.

---

<div class="post-metadata">

**Author:** ![Marcello](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@Marcello](https://forum.keycloak.org/u/Marcello)\
**Post date:** [November 22, 2021, 8:36am UTC](https://forum.keycloak.org/t/decision-strategy-affirmative-strategy-doesnt-behave-as-expected/12010/3 "2021-11-22T08:36:10Z")

</div>

+10  
We are facing similar issue, this seems to be strange and BIG issue for which there seem to be no answers from the Keycloak team.  
I’ve found similar questions, to which there are no answers:

- [https://stackoverflow.com/questions/69929923/keycloak-affirmative-strategy-doesnt-behave-as-expected](https://stackoverflow.com/questions/69929923/keycloak-affirmative-strategy-doesnt-behave-as-expected)
- [http://forum.keycloak.org/t/evaluate-permission-error/7492](http://forum.keycloak.org/t/evaluate-permission-error/7492)

@Keycloak , can you help us out?

---

<div class="post-metadata">

**Author:** ![sumitmudliar](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/sumitmudliar/32/4905_2.png) [@sumitmudliar](https://forum.keycloak.org/u/sumitmudliar)\
**Post date:** [January 25, 2022, 4:10pm UTC](https://forum.keycloak.org/t/decision-strategy-affirmative-strategy-doesnt-behave-as-expected/12010/4 "2022-01-25T16:10:43Z")

</div>

- 1  
Facing the same issue, is there an update on this?

---

<div class="post-metadata">

**Author:** ![pboehm](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/pboehm/32/4994_2.png) [@pboehm](https://forum.keycloak.org/u/pboehm)\
**Post date:** [February 9, 2022, 11:28am UTC](https://forum.keycloak.org/t/decision-strategy-affirmative-strategy-doesnt-behave-as-expected/12010/5 "2022-02-09T11:28:54Z")

</div>

I’m also facing this problem and after some remote debugging I have created a corresponding Github issue [https://github.com/keycloak/keycloak/issues/10086](https://github.com/keycloak/keycloak/issues/10086) and I have referenced this discussion.

---

<div class="post-metadata">

**Author:** ![pboehm](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/pboehm/32/4994_2.png) [@pboehm](https://forum.keycloak.org/u/pboehm)\
**Post date:** [February 10, 2022, 9:26am UTC](https://forum.keycloak.org/t/decision-strategy-affirmative-strategy-doesnt-behave-as-expected/12010/6 "2022-02-10T09:26:01Z")

</div>

After some more fiddling around with Keycloak Authz and thinking about the Keycloak source code I had debugged I found the solution:

The problem only occurs when no Authorization Scope is assigned to the resource. When you create some Authorization Scope and assign it to the resource the affirmative decision strategy with multiple permissions works as expected.

@davidep @sumitmudliar

---

<div class="post-metadata">

**Author:** ![davidep](https://avatars.discourse-cdn.com/v4/letter/d/71c47a/32.png) [@davidep](https://forum.keycloak.org/u/davidep)\
**Post date:** [February 10, 2022, 11:06am UTC](https://forum.keycloak.org/t/decision-strategy-affirmative-strategy-doesnt-behave-as-expected/12010/7 "2022-02-10T11:06:08Z")

</div>

thanks for your effort… I’ll give it a try
