Spring Security's CSRF protection blocks Keycloak administrative actions when configured with the default request matcher. This provides a CSRF request matcher that permits Keycloak administrative actions without the CSRF token.