To which kind of auth the Brute Force Protection is applied?

Hello,

To which kind of auth the Brute Force Protection is applied ?

  • Users with their password into the KeyCloak DB
    but also :
  • Users with their password into an external LDAP or Kerberos system ?
  • Client credentials flow auth ?

Thanks and regards