Skip to content

grommunio auth – Central Authentication, Single Sign-On, and Multi-Factor Security for Modern Enterprises

grommunio auth is the central identity and access management solution of the grommunio platform. Based on Keycloak, the solution enables Single Sign-On (SSO), Multi-Factor Authentication (MFA), passkeys, and seamless integration with existing Active Directory, LDAP, Microsoft Entra ID, and enterprise SSO environments. Users benefit from a consistent login experience across grommunio Web, grommunio Chat, grommunio Meet, grommunio Files, and other enterprise applications.

Why grommunio auth?

• One login for all grommunio services
• Integration with existing Active Directory and LDAP structures
• Multi-Factor Authentication and passkeys
• Support for OpenID Connect (OIDC) and SAML
• Centralized user and role management
• Multi-tenancy for enterprises and service providers
• Open-source technology based on Keycloak

One Authentication for the Entire grommunio Platform

grommunio-auth serves as the central authentication instance for the entire grommunio suite. Users log in once and receive secure access to authorized services such as grommunio-web, grommunio-chat, grommunio-meet, and grommunio-files. This reduces password silos and improves usability.

Single Sign-On for Existing Enterprise Environments

The solution was designed for integration into existing IT environments. Existing identity sources can continue to be used and enhanced with modern security features. Supported identity providers include Active Directory, LDAP, Microsoft Entra ID, Keycloak, as well as other OpenID Connect and SAML providers.

Multi-Factor Authentication for Modern Security Requirements

In addition to traditional passwords, grommunio-auth supports modern authentication methods such as TOTP, passkeys, WebAuthn, and FIDO2. This enables security policies to be implemented centrally and user accounts to be effectively protected.

Centralized User and Role Management

Users, groups, and permissions are managed centrally. Role models, access rights, and organizational structures can be enforced consistently across all connected applications.

Multi-Tenancy and Organizational Structures

Using so-called realms, different organizations, business units, or customers can be managed separately from one another. This is particularly suitable for larger organizations and managed service providers.

Open Standards Instead of Vendor Lock-In

grommunio-auth is based on Keycloak and supports open standards such as OpenID Connect, OAuth 2.0, SAML, LDAP, and WebAuthn. This keeps the authentication infrastructure flexible and extensible in the long term.

Typical Use Cases

Enterprises, public administration, educational institutions, healthcare organizations, managed service providers, and organizations with high requirements for security, compliance, and centralized user management.

Why ForgeOne?

ForgeOne supports organizations in the planning, implementation, and operation of grommunio-auth. This includes Active Directory integration, LDAP connectivity, SSO implementation, MFA rollouts, Keycloak migrations, high-availability concepts, and long-term support.

Frequently Asked Questions about grommunio-auth

What is grommunio-auth?Show answer Action: Open answer

grommunio-auth extends the grommunio platform with centralized authentication and single sign-on capabilities. The solution is based on Keycloak and supports modern standards such as OpenID Connect, OAuth2, and SAML.

This allows existing identity and user management systems to be integrated into the groupware platform.

What technology is grommunio-auth based on?Show answer Action: Open answer

grommunio-auth is based on Keycloak, an open-source identity and access management platform.

Keycloak supports:

  • Single Sign-On (SSO)
  • Multi-Factor Authentication (MFA)
  • User and role management
  • OpenID Connect
  • OAuth2
  • SAML
  • Identity federation

This makes grommunio-auth suitable for both small Linux environments and enterprise infrastructures.

Does grommunio-auth support Single Sign-On (SSO)?Show answer Action: Open answer

Yes. grommunio-auth supports centralized single sign-on architectures via OpenID Connect and SAML.

Users can authenticate using existing enterprise accounts without managing separate credentials within the groupware platform.

Can grommunio-auth be integrated with existing identity providers?Show answer Action: Open answer

Yes. The platform supports integration with existing identity and SSO environments.

Typical integrations include:

  • Keycloak
  • Microsoft Entra ID / Azure AD
  • Authentik
  • Okta
  • Active Directory Federation Services
  • Other OpenID Connect or SAML-compatible providers

This allows grommunio to operate as part of an existing identity strategy.

Does grommunio-auth support Multi-Factor Authentication (MFA)?Show answer Action: Open answer

Yes. Various multi-factor authentication mechanisms can be integrated through Keycloak.

These include:

  • TOTP
  • Authenticator apps
  • WebAuthn
  • Hardware tokens
  • Passwordless authentication

This enables organizations to implement centralized security policies consistently.

Can grommunio-auth be used with LDAP or Active Directory?Show answer Action: Open answer

Yes. Keycloak supports integration with existing LDAP and Active Directory environments.

User accounts can therefore be managed centrally and used for authentication within grommunio.

Does grommunio-auth support OpenID Connect?Show answer Action: Open answer

Yes. OpenID Connect (OIDC) is one of the core authentication standards within grommunio-auth.

This enables modern SSO architectures for Linux, cloud, and hybrid environments.

Can local login be disabled?Show answer Action: Open answer

Yes. In production SSO environments, local login can be completely disabled.

Authentication requests are then redirected directly to the centralized identity provider, creating a consistent login experience across all connected systems.

Is grommunio-auth suitable for enterprise environments?Show answer Action: Open answer

Yes. The solution is designed for production enterprise and Linux environments with centralized requirements for:

  • Identity management
  • Access control
  • Security policies
  • User management
  • Multi-factor authentication
  • Single sign-on

Thanks to its open-source foundation, the platform remains flexible and transparently extensible.

Can grommunio-auth be combined with other open-source platforms?Show answer Action: Open answer

Yes. Especially in combination with:

  • XWiki
  • OpenProject
  • Nextcloud
  • Keycloak
  • Linux infrastructures

fully integrated open-source collaboration platforms can be built.

This allows organizations to implement centralized identity and security concepts consistently across multiple systems.

Does grommunio-auth support digital sovereignty and open-source strategies?Show answer Action: Open answer

Yes. grommunio-auth is fully based on open-source technologies and can be operated within an organization’s own Linux or data center infrastructures.

This allows organizations to retain control over:

  • User management
  • Authentication processes
  • Security policies
  • Data storage
  • Infrastructure
  • Integrations

This makes the platform especially attractive for enterprises, public authorities, and organizations focused on digital sovereignty and European open-source strategies.

Free Initial Consultation