Currently, we only document the Keycloak "format" (username is the keycloak username, groups are "file-system-style paths"), but not the AD one (username is the Kerberos UPN, groups are distinguished names), or how it might differ between them (beyond a slight mention that there is a difference).
We should give examples for each, and/or give an easy example for how to query it yourself to see the data format that applies to your environment.
Currently, we only document the Keycloak "format" (username is the keycloak username, groups are "file-system-style paths"), but not the AD one (username is the Kerberos UPN, groups are distinguished names), or how it might differ between them (beyond a slight mention that there is a difference).
We should give examples for each, and/or give an easy example for how to query it yourself to see the data format that applies to your environment.