keycloak/server/sso/fqdn/path is originally an app setting, but is evaluated by other components, so it's also used an an UCRv. This leads to problems in setting, syncing and evaluting the value. On a broader picture this shows the inconsistencies between UCRv, app settings and additional configurational objects.
done, we now have the policy for the clients.