# External authentication (Oauth2) and Admin/Manager role

**URL:** <https://kanboard.discourse.group/t/external-authentication-oauth2-and-admin-manager-role/3627>\
**Category:** Questions\
**Created:** [April 30, 2026, 9:13pm UTC](https://kanboard.discourse.group/t/external-authentication-oauth2-and-admin-manager-role/3627 "2026-04-30T21:13:59Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![smirta](https://yyz2.discourse-cdn.com/free1/user_avatar/kanboard.discourse.group/smirta/32/2217_2.png) [@smirta](https://kanboard.discourse.group/u/smirta)\
**Post date:** [April 30, 2026, 9:13pm UTC](https://kanboard.discourse.group/t/external-authentication-oauth2-and-admin-manager-role/3627/1 "2026-04-30T21:13:59Z")

</div>

Dear all,

I have spent a couple of evenings to figure out what the options are to assign roles to users as one would do with `LDAP_GROUP_ADMIN_DN` when using LDAP. The user get authenticated through OIDC with keycloak using the Oauth2 plugin.

Because of the comment `// Enable/Disable groups synchronization when external authentication is used.` above `LDAP_GROUP_SYNC`, I thought it may be possible to authenticate using Oauth2 and then the user will be added to the group defined in `LDAP_GROUP_ADMIN_DN`. But that probably doesn’t work because the assignment of the role is happening on (LDAP) authentication and therefore our users will never pass this routine.

When I went through all the issues on gh and posts in here, I believe I read some posts where someone might have found a solution but didn’t share their solution.Anyone figured out how to do it or has some hints for me?

Thanks a million!
