Need a sanity check/questions for SSO migration (Authentik very likely candidate)

Hello! With some recent stuff that I read and upcoming big projects with our homelab I started to plan out bumping up security and QOL with the big thing being Domain/Active Directory (the other sysadmin half of this homelab is handling that) and SSO, which I am handling. After looking and researching it looks like Authentik is winning out over Authelia which is a shame because I do like what I see with Authelia but the lack of SAML atm is stopping two services from working with SSO. Anyway onto the sanity check/questions I need help with because a lot of this is extremely new to me: One, we're planning on using Active Directory (LDAPS) as the main source for users which looks straightforward but from that point on, the users can just log in with their domain credentials and Authentik handles the authentication from that point with the various services via Oauth, SAML, etc? Once the services are configured to talk to Authentik and the user is setup in AD that is. Two, what happens with existing accounts? I know that migrating/merging users will vary from service to service but is there a way to tell Authentik "use x credentials for y application for this user" or will that be treated as a new account regardless what happens? We don't have much where that's a concern but the ones that do are critical (Actual Budget for example!) Thanks all!

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论