# Link existing account to federation provider

**URL:** <https://forum.keycloak.org/t/link-existing-account-to-federation-provider/13927>\
**Category:** Configuring the server\
**Tags:** ldap\
**Created:** [February 28, 2022, 4:41pm UTC](https://forum.keycloak.org/t/link-existing-account-to-federation-provider/13927 "2022-02-28T16:41:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ThoreKr](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/thorekr/32/7713_2.png) [@ThoreKr](https://forum.keycloak.org/u/ThoreKr)\
**Post date:** [February 28, 2022, 4:41pm UTC](https://forum.keycloak.org/t/link-existing-account-to-federation-provider/13927/1 "2022-02-28T16:41:59Z")

</div>

I’m currently trying to figure out whether user federation is suitable for my use case.

It looks like this:

Users can freely register and should only be stored in the keycloak database.  
There is an initial set of users which should be imported from ldap and synchronized into groups if necessary.

Now it can happen that an existing (registred) account is added to ldap or at some point removed from ldap.  
In these cases the group mappings should be updated accordingly but the user in keycloak should not be deleted.

In a small test I tried to register a user first and then enable ldap synchronization (with and intended collision), which yields the following error:

```auto
User with ID '00a8c928-97be-1037-9a8e-e5c6150c1234' is not updated during sync as he already exists in Keycloak database but is not linked to federation provider 'ldap'

```

In theory this fits my use case as users should not be simply synchronized by nickname. However, is there a way to later link it to the federation provider?  
Setting the LDAP\_ID or LDAP\_ENTRY\_DN manually is rejected as these attributes are internal.

---

<div class="post-metadata">

**Author:** ![kevinmartins](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/kevinmartins/32/2825_2.png) [@kevinmartins](https://forum.keycloak.org/u/kevinmartins)\
**Post date:** [March 1, 2022, 4:15pm UTC](https://forum.keycloak.org/t/link-existing-account-to-federation-provider/13927/2 "2022-03-01T16:15:03Z")

</div>

Hi, I don’t know if this is exactly what you need but if you click on your user you should have the indentity provider link like this.

 ![image](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/7/72a7004325288df3f9e9478f5b1dfd505a9bd85a.png)

---

<div class="post-metadata">

**Author:** ![ThoreKr](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/thorekr/32/7713_2.png) [@ThoreKr](https://forum.keycloak.org/u/ThoreKr)\
**Post date:** [March 1, 2022, 5:53pm UTC](https://forum.keycloak.org/t/link-existing-account-to-federation-provider/13927/3 "2022-03-01T17:53:49Z")

</div>

Thank you for the response. That seems like the functionality I’m looking for, but I don’t have that tab. Probablly because it is for identity brokering but not user federation.

So probably I’ll have to revert to scripting or having another keycloak in front of the ldap.

---

<div class="post-metadata">

**Author:** ![havarnov](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/havarnov/32/7540_2.png) [@havarnov](https://forum.keycloak.org/u/havarnov)\
**Post date:** [January 25, 2023, 2:18pm UTC](https://forum.keycloak.org/t/link-existing-account-to-federation-provider/13927/4 "2023-01-25T14:18:19Z")

</div>

@ThoreKr did you figure out how to do this?

---

<div class="post-metadata">

**Author:** ![davsum](https://avatars.discourse-cdn.com/v4/letter/d/a88e57/32.png) [@davsum](https://forum.keycloak.org/u/davsum)\
**Post date:** [February 9, 2023, 7:40pm UTC](https://forum.keycloak.org/t/link-existing-account-to-federation-provider/13927/5 "2023-02-09T19:40:48Z")

</div>

LDAP\_ID, LDAP\_ENTRY\_DN, createTimestamp, and modifyTimestamp are read only attributes that you cannot added through the web interface. You cannot delete them either. As long as an ldap federation is enabled they will be present on accounts imported from ldap or created in keycloak and added to ldap. To remove them you have to delete them from the table in your database or delete the user.

It is possible to link an existing keycloak user to an ldap user object. You have to add the LDAP\_ID, LDAP\_ENTRY\_DN, createTimestamp, and modifyTimestamp attributes to the user\_attribute table and update the federation\_link column on the users record in the user\_entity table in the keycloak database. You will have to modify the database with a scripting language and appropriate library for your database. Once they are present the associated keycloak user will have a federation link on their details page.

Federation Link SQL  
UPDATE user\_entity  
SET federation\_link = ‘[LDAP\_UUID]’ WHERE id = ‘[USER\_UUID]’;

Federation Attributes SQL  
INSERT INTO  
user\_attribute (name, value, user\_id, id)  
VALUES  
(‘LDAP\_ID’, ‘[LDAP\_USER\_GUID]’, ‘[KEYCLOAK\_USER\_ID]’, ‘[RANDOM\_UUID]’),  
(‘LDAP\_ENTRY\_DN’, ‘[LDAP\_USER\_DN]’, ‘[KEYCLOAK\_USER\_ID]’, ‘[RANDOM\_UUID]’),  
(‘createTimestamp’, ‘[LDAP\_USER\_CREATED]’, ‘[KEYCLOAK\_USER\_ID]’, ‘[RANDOM\_UUID]’),  
(‘modifyTimestamp’, ‘[LDAP\_USER\_MODIFIED]’, ‘[KEYCLOAK\_USER\_ID]’, ‘[RANDOM\_UUID]’);

[LDAP\_USER\_GUID] = the uuid for the object in ldap, in AD it is objectGUID.  
[KEYCLOAK\_USER\_ID] = the uuid of the keycloak user, the ID attribute  
[LDAP\_USER\_DN] = distinguishedName attribute of the object in ldap  
[LDAP\_USER\_CREATED] = the created timestamp for the object in ldap. In AD it is whenCreated  
[LDAP\_USER\_MODIFIED] = the modified timestamp for the object in ldap. In AD it is whenModified  
[RANDOM\_UUID] = randomly generated uuid. Needs to be provided as the column will not generate its own value, at least in postgresql it won’t.
