# Remove useless identity-provider instances

**URL:** <https://forum.keycloak.org/t/remove-useless-identity-provider-instances/27653>\
**Category:** Getting advice\
**Tags:** authentication\
**Created:** [August 29, 2024, 12:26pm UTC](https://forum.keycloak.org/t/remove-useless-identity-provider-instances/27653 "2024-08-29T12:26:26Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![jol002](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/jol002/32/2418_2.png) [@jol002](https://forum.keycloak.org/u/jol002)\
**Post date:** [August 29, 2024, 12:26pm UTC](https://forum.keycloak.org/t/remove-useless-identity-provider-instances/27653/1 "2024-08-29T12:26:26Z")

</div>

I created three User federation-instances, to make failover possible:  
ldap 01 is connected to ldaps://_xxxx_dc01._xxx_:636  
ldap 02 is connected to ldaps://_xxxx_dc02._xxx_:636  
ldap 03 is connected to ldaps://_xxxx_dc03._xxx_:636  
But it turned out, that does not work for failover.

One year later:  
so I removed the instances ldap 02 and ldap03.  
In ldap01 I configured the connection as follows (3 servers, space-separated):  
ldaps://_xxxx_dc01._xxx_:636 ldaps://_xxxx_dc02._xxx_:636 ldaps://_xxxx_dc03._xxx_:636

This works, however, all users that were not resolved via ldap01 in the old situation, need to configure their authenticatior with the appearing QR-code while logging in.

I did this on the test-environment, but not yet on production. So, to avoid this problem on production, what can be done?

Is it possible to force the users to ldap 01 in the postgres-database?  
Or is there some other solution?

Who can help me out:?
