Common causes of lockout
- Forgotten or lost admin password: The initial credentials were not recorded or were changed and then lost.
- Account locked after failed attempts: Keycloak locks accounts after a configurable number of consecutive failed login attempts.
- Realm misconfiguration: An administrative change to the Keycloak realm settings may have inadvertently restricted admin access.
Before attempting recovery
Check whether any other administrator account exists on the appliance. If a second administrator’s credentials are available, that account can be used to reset the primary admin password without requiring the recovery procedure below. To check: ask other administrators on your team if they have working credentials before proceeding with the manual recovery steps.Recovery using the BMC console
1
Connect to the BMC management interface
Connect a laptop to the BMC management port on the front of the appliance. Open a browser and navigate to the BMC’s address (documented on the delivery record). Log in to the BMC with the BMC credentials from the delivery record.
2
Open a remote console session
In the BMC interface, open the remote console or KVM session. This gives you direct OS-level access to the appliance independent of the Keycloak web interface.
3
Run the admin credential reset utility
In the remote console session, run the admin credential reset utility on the appliance. This is a last-resort administrative procedure that resets the Keycloak admin password directly on the appliance without requiring an active web session. When prompted, supply a new password for the admin account.If you are unsure which command to run, contact support — they can guide you through this step for your specific appliance revision.
4
Log in and verify access
Return to a browser on a connected laptop, navigate to the Keycloak admin console URL (see Application URLs), and log in with the new credentials you just set.
5
Change the password to a secure value
Once logged in, immediately change the admin password to a strong, securely stored value. Update any team documentation that records admin credentials.
If you are unable to reach the BMC console or the credential reset does not restore access, escalate to support. See When to Escalate for guidance on what information to gather before contacting them.