I saw that you can integrate keystone with AD, but it looks like this is looking for a particular OU and Group structure. Azure AD doesn't have an OU structure.

I was thinking to integrate keystone with Azure AD in order to use 3rd party identity providers such as google/facebook. Can this be done with keystone? If you can't use Azure AD would this be possible with an on prem ADFS installation that syncs up with Azure?

I read this document which seems to indicate that they are at least thinking about keystone and identity federation. (

Can anyone provide thoughts or insights?

I wanted to add another comment here as I just recently noticed that I installed my lab with Havana so I upgraded it to IceHouse. I see that keystone has a new v3 API, but I can't seen to find much documentation about it. For instance I found this: (

The documentation seems to want you to install httpd on your keystone server? I can't make sense of this.

My thought is that it would work like: User goes to a frontend website and attempts to login with an address. This isn't an account we store locally so the password option would grey out and redirect the user to the external identity provider and then the correct authentication page would be displayed (google) so that they can login with their account and ...(more)

