Using Keycloak as the Identity source for AWS GovCloud IAM Identity Center

I’m trying to configure Keycloak as the identity source for AWS GovCloud IAM Identity Center. I’m also using LDAP WIndows AD on the backend. I’m able to log in. However, I get an error saying, “You do not have any applications.” Here’s an example of a permission set I’m trying to pass. arn:aws-us-gov:sso:::permissionSet//ps-d802acc41a21e7b7. I’d like just to configure it in AD Groups and leave Keycloak out as much as possible. Thanks