Known limitations

Realm administration is a new feature that is under active development. As of Q3 2026, the following limitations are known:

  • Some global permissions cannot be restricted by realm
    “View Log Files” and “View Authentication Tokens” are global permissions associated with corresponding user roles in the IAM configuration. A realm administrator who holds one of these user roles can see information that they may not be authorized to view. Currently, these permissions cannot be restricted to specific realms. This includes the following information:
    • “View Log Files” permission: All user logs
    • “View Authentication Tokens” permission: All usernames associated with the listed authentication tokens
  • Permission removal is not propagated
    The permissions assigned to a subrole cannot exceed those of its parent role. However, when a realm admin removes permissions from the parent role, currently these permissions are not automatically also removed from its subroles; this has to be done manually.
  • No termination of realm admin sessions if permissions change
    Two realm admins, A and B, are logged in simultaneously. If realm admin A removes realm roles from realm admin B, the change does not take effect until realm admin B logs in again. The same applies if realm admin A locks realm admin B.
  • Role conflict with connected systems
    Roles coming from a connected system, such as Active Directory, may have the same name as realm roles or user roles. This may lead to a cumulation of permissions, giving realm admins permissions they should not have.
  • Only users with admin roles can access the Adminapp
    This applies to both global admin roles set in the IAM configuration and to realm admin roles.
  • Possible information leaking when creating a new realm
    When creating a new delegation, an admin can check whether a realm already exists.