Windows Desktop + AD + Keycloak

Currently we have a number of systems using RCdevs to provide 2fa in a closed system with no internet access, I am interested in using Keycloak to replace rcdevs to provide 2fa TOTP tokens for Desktop user login to their machines.