To synchronize email addresses, last names, and first names of users of an
identity provider other than AD FS with those of Common Services, you must map identity provider user
attributes to Keycloak user attributes. Note that this mapping is required only when
synchronization is needed.
The settings differ depending on the
federation protocol used for linking with the identity provider.