Navigation
10.18. Set Up SSO with Keycloak, Google Workspace, or Microsoft 365
Configure staff SSO with your Keycloak realm in Community or Enterprise Edition, or link Google Workspace and Microsoft 365 accounts in Enterprise Edition.
Single Sign-On (SSO) Management
Single Sign-On allows users to log in to AlgaPSA using their existing credentials from Keycloak, Google Workspace, or Microsoft 365. This lets an MSP use its staff identity provider for daily PSA access. Administrators configure SSO from Settings > Security > Single Sign-On.
Availability: Keycloak is available in Community Edition and Enterprise Edition and is the SSO option in Community Edition. Google Workspace and Microsoft 365 SSO require Enterprise Edition.
Configure Keycloak (OpenID Connect)
Use your own Keycloak realm to authenticate existing internal users. Users are matched by email to their AlgaPSA accounts; Keycloak sign-in does not create users. Before setup, create the staff accounts in AlgaPSA and confirm that their email addresses match their Keycloak identities.
Figure 1: The Keycloak card under Security > Single Sign-On.
- Open Settings > Security > Single Sign-On and find Keycloak / OpenID Connect.
- Create a confidential OpenID Connect client in your Keycloak realm and allow the redirect URI displayed in AlgaPSA.
- Complete these fields:
| Field | What to enter |
|---|---|
| Keycloak server URL | The public server URL, for example https://keycloak.example.com. Enter the realm separately. |
| Realm | The realm name exactly as it appears in Keycloak. |
| Client ID | The ID of the confidential client created for AlgaPSA. |
| Client secret | The client's secret. On later edits, leave it blank to keep the saved secret. |
- Select Verify and save. AlgaPSA checks the realm's OpenID discovery endpoint and verifies its issuer before saving. The issuer combines the server URL and realm, for example
https://keycloak.example.com/realms/northpoint. - Expand Advanced: custom identity provider routing and add your staff login domain. In Enterprise Edition, claim and verify that domain; Community Edition uses domain registration without ownership verification.
- Test sign-in with an existing staff member's email address. The Keycloak button appears only when provider discovery succeeds and returns Keycloak for that login. If it does not appear, review the saved realm configuration and login-domain routing.
Check that the test opens the intended staff account. Keep password-based access available while validating the realm and email matching.
Figure 2: Once discovery succeeds, Sign in with Keycloak appears on the sign-in page beside the other providers.
Link Google or Microsoft SSO from Your Profile
In Enterprise Edition, individual users can link their AlgaPSA account to Google or Microsoft directly from their profile settings.
Steps to Link Your Account
- Click on your profile avatar in the top right corner of AlgaPSA.
- Select Profile from the dropdown menu.
- Navigate to the Single Sign-On tab.
- In the Secure your account with SSO section:
- Confirm your email address shown in the Signed in as field.
- Enter your Current password.
- Click the Verify Credentials button.
- Once verified, a message will appear: "Credentials verified. Choose a provider below to finish linking your account."
- In the Connect a provider section, click on your desired provider:
- Google Workspace - Sign in with your Google-managed identity.
- Microsoft 365 (Azure AD) - Sign in with your Azure Active Directory account.
- You will be redirected to your provider's login page. Select or sign in with the account you want to link.
- After successful authentication, you will be redirected back to AlgaPSA.
- Your linked account will appear in the Linked accounts section, showing:
- The provider badge (Google or Microsoft)
- Your linked email address
- The date the account was linked
- The last time SSO was used
- Click Save Changes to finalize the setup.
Administrator SSO Management in Enterprise
Navigate to Settings > Security, then open the Single Sign-On tab in Security Settings. This section is for administrators to configure providers, link or unlink existing users, and manage SSO behavior in AlgaPSA.
Single Sign-On Assignment (Linking and Unlinking Existing Users)
Steps to Link Users
This process is used to connect existing internal users to your configured SSO provider.
- Under the Single Sign-On Assignment section, locate the Choose provider toggle
- Select your provider by clicking on the corresponding tab: Google Workspace or Microsoft 365 (Azure AD).
- Ensure the Action toggle is set to Link selected users.
- In the Find internal users search bar, you can search for users by their email.
- Check the box next to the user(s) you want to link. You can select multiple users.
- (Optional): Click Preview assignment to review the actions before execution. It will display below the list of users.
- Click the Link accounts button to finalize the SSO assignment for the selected users.
Steps to Unlink Users
Unlinking a user returns their account to their original password-based sign-in method.
- Under the Single Sign-On Assignment section, select your provider (Google Workspace or Microsoft 365).
- Change the Action toggle to Unlink selected users.
- In the Find internal users section, find and check the box next to the user(s) you wish to unlink.
- (Optional): Click Preview unlink to review the actions before execution. It will display below the list of users.
- Click the Unlink accounts button to remove the SSO link for the selected users.
Automatically Set Up SSO for New Users
This setting ensures that any new internal staff member added to AlgaPSA after this feature is enabled will be automatically provisioned for SSO if their email matches a configured provider.
- To enable this feature, locate the setting Automatically set up SSO for new internal users.
- Toggle the switch to the ON position (it will turn purple).
Previewing Assignment
The preview function is highly recommended when processing multiple users to avoid unintended changes.
-
Select your Provider and the desired Action (Link or Unlink).
-
Select the user(s) from the internal user list.
-
Click the Preview assignment (or Preview unlink) button.
-
A Preview results section will appear below the user list, detailing:
- Processed Users: The total number of selected users.
- Linked/Unlinked: How many accounts will have the action applied.
- Already Linked/Unlinked: How many accounts already have the desired status and will be skipped.
- Skipped (Inactive): Accounts that cannot be processed (e.g., inactive users).
Related identity features
This page covers SSO for your own internal AlgaPSA users, including email matching through Keycloak. Client access and automated user lifecycle management are separate workflows:
- 13.9. Let Client Portal Users Sign In with Their Own Microsoft Accounts: let client contacts use their Microsoft identities, with an Entra access group deciding who gets portal access. Internal and client auto-linking are separate switches, so enabling auto-link here does not enable it for client contacts.
- 10.19. Provision Internal Users from Microsoft Entra with SCIM 2.0: let Microsoft Entra deactivate and reactivate internal users, revoking their sessions immediately. Keycloak email matching does not provision or deactivate AlgaPSA accounts.
