Setting up a generic SAML federation in Keycloak with another identity provider has some drawbacks. For example, if you want all group claims from the third-party IdP to be included in your access ...