Cannot create Identity Provider Links without manage-realm role

Keycloak 11.0. Trying to set up a realm administrator, “Joe,” who just has privileges limited to add, delete and modify users. But Joe cannot add a new identity provider link through the realm admin console because under the Identity Provider Links tab, after clicking the Create button, the Identity Provider, Identity Provider User Id, and Identity Provider Username fields are all inactive and Joe sees the red circle-with-a-slash when hovering over those fields. I have to grant the manage-realm role under Joe’s Role Mappings > Client Roles > realm-management > manage-realm. But that would give Joe access to many other realm-level privileges which are extremely undesirable in a production environment. Any help would be appreciated!