Hey everyone,
How do you do user management, I have a small handful of users that want one password for physical machines and for web apps. I was looking at KanIDM but I was wondering what other people use?
Edit: I would like to only use one piece of software if possible.


I would recommend keycloak. I can basically do everything related to webapps authentication (OIDC, 2FA, etc)… except working as an LDAP/AD server, which typically used to enable login to physical machine using the network account. But, it has built-in LDAP provider support, which mean you can use OpenLDAP to host the accounts of your users (so they can use LDAP authentication on their own machine), and point keycloak to that OpenLDAP instance to allow your users to login to your webapps using their OpenLDAP account.
Keycloak is nice, but probably overkill for what OP needs. Keep it simple.