bettersorted Logo
Office building of a medium-sized company
AI Automation

Keycloak in SMEs: use, benefits, effort

AuthorMuhamed Alahmed
Published on
Reading time4 min
In short

Keycloak is a mature open-source solution for central login and access management under the Apache 2.0 license, backed by Red Hat and the Cloud Native Computing Foundation. In SMEs, it is suitable for companies with many users, multiple locations, partner access, or complex permissions. The setup effort is higher than with leaner solutions.

The most important points at a glance

  • Keycloak: Apache 2.0, maintained by Red Hat, CNCF project.
  • Strong with many users, locations, partner access.
  • More setup and operational effort than Authentik.
  • Commercial Support available.

Keycloak is a mature open-source solution for central login (Single Sign-On) and access management under Apache-2.0 license. It is maintained by Red Hat; since 2023 it has been a project of the Cloud Native Computing Foundation. In the mid-sized business sector, Keycloak is particularly suitable for companies with many users, multiple locations, partner or customer access and complex permissions. The setup effort is higher than with leaner solutions.

Typical use cases in mid-sized businesses

  • Employee SSO: One login for Nextcloud, AI tools, ERP web applications and specialist software.
  • Multiple locations or entities: separate areas (“Realms”) with their own rules under one system.
  • Partner and customer portals: access for external users, separated from internal accounts.
  • Integration of existing directories: Active Directory or LDAP remain the source, Keycloak handles modern authentication.
  • Custom applications: Web portals and apps use Keycloak for authentication and permissions.
Administrator with laptop in the data center

Benefits

  • Fully free license: Apache 2.0, no enterprise tier with locked features.
  • Scope of functions: fine-grained permissions, strong authentication, federation with other identity providers.
  • Standards: OpenID Connect, OAuth 2.0, SAML – broad compatibility.
  • Stability:large provider, large community, extensive experience in use.
  • Support available:commercial support via Red Hat or specialized service providers.
  • Independence:operation in Germany, no dependence on a cloud provider – see Avoid vendor lock-in.

What effort you should expect

  • Planning: Carefully think through roles, groups, areas and integrations.
  • Setup: more extensive than with Authentik; experience with identity management helps.
  • Operation: regular updates, monitoring, data backup, high availability with many users.
  • Expertise: Someone must know Keycloak well, either internally or through a service provider.

For smaller environments, this is often more than necessary – then it is worth taking a look at Authentik. The direct comparison shows Keycloak vs. Authentik.

Security and data protection

  • Keycloak is the central keyfor all systems – securing, updates, and monitoring have top priority.
  • Two-factor login for everyone, at least for administrators.
  • Operate in Germany, store logs separately and securely.
  • Share only the necessary information with applications (data minimization).

Introduction in SMEs

  1. Inventory: applications, directories, user groups, external access.
  2. Target state: areas, roles, login rules, two-factor requirement.
  3. Pilot with one department and two to three applications.
  4. Gradual expansion, training of administrators.
  5. Operating concept: updates, monitoring, emergency access, documentation.

For technology enthusiasts

  • Keycloak is based on Java (Quarkus) and requires a relational database, usually PostgreSQL.
  • For high availability, multiple instances are operated in the cluster.
  • Configuration can be versioned via exports or configuration-as-code tools.

bettersorted relies on open, transparent components – operated on servers in Germany and bundled in the automaisa Hub. We provide manufacturer-neutral consulting, are a BAFA-registered consultant and an authorized INQA coach. The Consulting and guided implementation can be handled via the INQA Coaching with 80% funding; the appropriate path is shown by the Funding Check. For an initial, non-binding consultation: Contact.

Example: dealer portal and employee SSO

An illustrative scenario: a machinery manufacturer with 300 employees operates a portal for dealers and service partners. Keycloak provides two separate areas: employees sign in via the existing Active Directory, partners via their own accounts with two-factor authentication. Both use the same web applications, but only see what is enabled for them.

Plan operations realistically

  • Two instances for failover resilience with many users
  • Regular updates with testing in a test environment
  • Monitoring of login failures and unusual access attempts
  • Documented configuration so that knowledge does not depend on one person

Costs and funding

For the introduction of Keycloak, there are no license costs for open-source tools. Costs arise for Setup (planning, installation, integration, testing), Operation (server or hosting in Germany, updates, monitoring, data backup) and Support (training, rules, contact person). We do not quote fixed prices because scope and initial situation vary greatly.

Eligible for funding is the consulting and guided implementation: The INQA-Coaching covers 80% of coaching costs nationwide (up to €11,520, vouchers until 30.06.2028); a preliminary analysis is subsidized by the BAFA consulting grantat 80% in the new federal states, Lüneburg and Trier, otherwise 50% – for applications submitted by 31.12.2026.

Frequently asked questions

What is Keycloak?

An open-source solution for centralized login and access management (Identity and Access Management), under the Apache-2.0 license, supported by Red Hat and the Cloud Native Computing Foundation.

Is Keycloak suitable for mid-sized companies?

Yes, especially with many users, multiple locations, external access, or complex permissions. For very small environments, a leaner solution may be sufficient.

What does Keycloak cost?

The software is free. Costs arise for servers, setup, operation, and optional commercial support.

Can Keycloak connect to Active Directory?

Yes. Keycloak can use existing directories such as Active Directory or LDAP as a user source and build a modern login on top of them.

As of October 2026. Models, versions, and licenses change quickly – before making a decision, check the current license with the provider.

Portrait of Muhamed Alahmed, founder of bettersorted
About the author

Muhamed Alahmed

With over 10 years’ experience in IT, I develop solutions that not only work from a technical perspective, but also create real added value and open up new possibilities.

More about bettersorted →

More articles

Newsletter

Stay up to date on AI topics

Short updates on AI automation, funding programs and new posts — no spam, unsubscribe anytime.

We use Brevo as our marketing platform. By submitting, you agree that your data will be transferred according to Brevo's privacy policy .

CallEmailContact form