Restructure IAM documentation (#112929)
Co-authored-by: Misi <mgyongyosi@users.noreply.github.com>
This commit is contained in:
@@ -270,7 +270,7 @@ With the new user interface (UI), you can now configure SAML without needing to
|
||||
|
||||
The SAML UI is available in Grafana Enterprise, Cloud Pro, and Advanced. It's user-friendly, with clear instructions and helpful prompts to guide you through the process.
|
||||
|
||||
For more information on how to set up SAML using the Grafana UI, refer to [Configure SAML authentication using the Grafana user interface](../../setup-grafana/configure-security/configure-authentication/saml-ui/).
|
||||
For more information on how to set up SAML using the Grafana UI, refer to [Configure SAML authentication using the Grafana user interface](../../setup-grafana/configure-access/configure-authentication/saml-ui/).
|
||||
|
||||
### Case-insensitive usernames and email addresses
|
||||
|
||||
|
||||
@@ -439,7 +439,7 @@ Grafana now supports GitLab OIDC through the `GitLab` OAuth provider in addition
|
||||
This change also allows Grafana to reduce the access scope to only the required scopes for authentication and authorization, instead
|
||||
of full read API access.
|
||||
|
||||
To learn how to migrate your GitLab OAuth2 setup to OIDC, refer to our [GitLab authentication documentation](../../setup-grafana/configure-security/configure-authentication/gitlab/).
|
||||
To learn how to migrate your GitLab OAuth2 setup to OIDC, refer to our [GitLab authentication documentation](../../setup-grafana/configure-access/configure-authentication/gitlab/).
|
||||
|
||||
### Google OIDC and Team Sync support
|
||||
|
||||
@@ -451,7 +451,7 @@ Grafana now supports Google OIDC through the `Google` OAuth provider in addition
|
||||
|
||||
This release also adds support for Google OIDC in Team Sync. You can now easily add users to teams by using their Google groups.
|
||||
|
||||
To learn how to migrate your Google OAuth2 setup to OIDC and how to set up Team Sync, refer to our [Google authentication documentation](../../setup-grafana/configure-security/configure-authentication/google/).
|
||||
To learn how to migrate your Google OAuth2 setup to OIDC and how to set up Team Sync, refer to our [Google authentication documentation](../../setup-grafana/configure-access/configure-authentication/google/).
|
||||
|
||||
## Plugins
|
||||
|
||||
|
||||
@@ -459,7 +459,7 @@ This is useful if you want to limit the access users have to your Grafana instan
|
||||
|
||||
We've also added support for controlling allowed groups when using Google OIDC.
|
||||
|
||||
Refer to the [Google Authentication documentation](http://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-security/configure-authentication/google/) to learn how to use these new options.
|
||||
Refer to the [Google Authentication documentation](http://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-access/configure-authentication/google/) to learn how to use these new options.
|
||||
|
||||
### Configure refresh token handling separately for OAuth providers
|
||||
|
||||
@@ -471,7 +471,7 @@ With Grafana v9.3, we introduced a [feature toggle](https://grafana.com/docs/gra
|
||||
|
||||
With the current release, we've introduced a new configuration option for each OAuth provider called `use_refresh_token` that allows you to configure whether the particular OAuth integration should use refresh tokens to automatically refresh access tokens when they expire. In addition, to further improve security and provide secure defaults, `use_refresh_token` is enabled by default for providers that support either refreshing tokens automatically or client-controlled fetching of refresh tokens. It's enabled by default for the following OAuth providers: `AzureAD`, `GitLab`, `Google`.
|
||||
|
||||
For more information on how to set up refresh token handling, please refer to [the documentation of the particular OAuth provider.](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-security/configure-authentication/).
|
||||
For more information on how to set up refresh token handling, please refer to [the documentation of the particular OAuth provider.](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-access/configure-authentication/).
|
||||
|
||||
{{< admonition type="note" >}}
|
||||
The `use_refresh_token` configuration must be used in conjunction with the `accessTokenExpirationCheck` [feature toggle](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-grafana/feature-toggles/). If you disable the `accessTokenExpirationCheck` feature toggle, Grafana won't check the expiration of the access token and won't automatically refresh the expired access token, even if the `use_refresh_token` configuration is set to `true`.
|
||||
|
||||
@@ -407,4 +407,4 @@ When anonymous access has been enabled, any device which accesses Grafana in the
|
||||
|
||||
{{< youtube id="B72X3_9e-ds" >}}
|
||||
|
||||
[Documentation](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-security/configure-authentication/grafana/)
|
||||
[Documentation](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-access/configure-authentication/grafana/)
|
||||
|
||||
@@ -219,7 +219,7 @@ We are working on adding complete support for configuring all other supported OA
|
||||
|
||||
{{< youtube id="xXW2eRTbjDY" >}}
|
||||
|
||||
[Documentation](https://grafana.com/docs/grafana/next/setup-grafana/configure-security/configure-authentication/)
|
||||
[Documentation](https://grafana.com/docs/grafana/next/setup-grafana/configure-access/configure-authentication/)
|
||||
|
||||
## Data sources
|
||||
|
||||
|
||||
@@ -376,7 +376,7 @@ If you manage your users using Grafana's built-in basic authorization as an iden
|
||||
|
||||
Starting with Grafana v11.0, you can enable an opinionated strong password policy feature. This configuration option validates all password updates to comply with our strong password policy.
|
||||
|
||||
To learn more about Grafana's strong password policy, refer to the [documentation](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-security/configure-authentication/grafana/#strong-password-policy).
|
||||
To learn more about the strong password policy in Grafana, refer to the [documentation](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-access/configure-authentication/grafana/#strong-password-policy).
|
||||
|
||||
### Anonymous users are billed in Grafana Enterprise
|
||||
|
||||
@@ -388,6 +388,6 @@ We are announcing a license change to the anonymous access feature in Grafana 1
|
||||
|
||||
**Affected Grafana versions**
|
||||
|
||||
[Anonymous authentication](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-security/configure-authentication/grafana/#anonymous-authentication) is disabled by default in Grafana Cloud. This licensing change only affects Grafana Enterprise (self-managed) edition. Anonymous users will be charged as active users in Grafana Enterprise.
|
||||
[Anonymous authentication](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-access/configure-authentication/grafana/#anonymous-authentication) is disabled by default in Grafana Cloud. This licensing change only affects Grafana Enterprise (self-managed) edition. Anonymous users will be charged as active users in Grafana Enterprise.
|
||||
|
||||
[Documentation](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-security/configure-authentication/grafana/#anonymous-devices)
|
||||
[Documentation](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-access/configure-authentication/grafana/#anonymous-devices)
|
||||
|
||||
@@ -254,7 +254,7 @@ This is a longstanding feature request from the community. We collaborated with
|
||||
|
||||
For Generic OAuth and Okta, you can configure the claim (using the `org_attribute_path` setting) that contains the organizations which the user belongs to. Other OAuth providers use the same attribute for organization mapping that is used for group mapping: Entra ID (previously Azure AD), GitLab and Google use the current user’s Groups, and GitHub uses the user’s Teams.
|
||||
|
||||
To configure organization mapping for your instance, please check the documentation for the OAuth provider you are using in the [Grafana documentation](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-security/configure-authentication/). You can find an example of how to configure organization mapping on each OAuth provider page under the **Org roles mapping example** section.
|
||||
To configure organization mapping for your instance, please check the documentation for the OAuth provider you are using in the [Grafana documentation](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-access/configure-authentication/). You can find an example of how to configure organization mapping on each OAuth provider page under the **Org roles mapping example** section.
|
||||
|
||||
### Better SAML integration for Azure AD
|
||||
|
||||
@@ -266,7 +266,7 @@ When setting up Grafana with Azure AD using the SAML protocol, the Azure AD Grap
|
||||
|
||||
With Grafana 11.2, we offer a mechanism for setting up an application as a Service Account in Azure AD and retrieving information from Graph API.
|
||||
|
||||
Please refer to our [documentation](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-security/configure-authentication/saml/#configure-a-graph-api-application-in-azure-ad) on how to set up an Azure AD registered application for this setup.
|
||||
Please refer to our [documentation](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-access/configure-authentication/saml/#configure-a-graph-api-application-in-azure-ad) on how to set up an Azure AD registered application for this setup.
|
||||
|
||||
### API support for LDAP configuration
|
||||
|
||||
|
||||
@@ -225,11 +225,11 @@ This release includes a series of features that build on our new usage analytics
|
||||
|
||||
### SAML Role and Team Sync
|
||||
|
||||
SAML support in Grafana Enterprise is improved by adding Role and Team Sync. Read more about how to use these features in the [SAML team sync documentation](../../setup-grafana/configure-security/configure-authentication/saml/#configure-team-sync).
|
||||
SAML support in Grafana Enterprise is improved by adding Role and Team Sync. Read more about how to use these features in the [SAML team sync documentation](../../setup-grafana/configure-access/configure-authentication/saml/#configure-team-sync).
|
||||
|
||||
### Okta OAuth Team Sync
|
||||
|
||||
Okta gets its own provider which adds support for Team Sync. Read more about it in the [Okta documentation](../../setup-grafana/configure-security/configure-authentication/okta/).
|
||||
Okta gets its own provider which adds support for Team Sync. Read more about it in the [Okta documentation](../../setup-grafana/configure-access/configure-authentication/okta/).
|
||||
|
||||
## Changelog
|
||||
|
||||
|
||||
@@ -146,11 +146,11 @@ Insights:
|
||||
|
||||
### SAML single logout
|
||||
|
||||
SAML’s single logout (SLO) capability allows users to log out from all applications associated with the current identity provider (IdP) session established via SAML SSO. For more information, refer to the [docs](../../setup-grafana/configure-security/configure-authentication/saml/#single-logout).
|
||||
SAML’s single logout (SLO) capability allows users to log out from all applications associated with the current identity provider (IdP) session established via SAML SSO. For more information, refer to the [docs](../../setup-grafana/configure-access/configure-authentication/saml/#single-logout).
|
||||
|
||||
### SAML IdP-initiated single sign on
|
||||
|
||||
IdP-initiated single sign on (SSO) allows the user to log in directly from the SAML identity provider (IdP). It is disabled by default for security reasons. For more information, refer to the [docs](../../setup-grafana/configure-security/configure-authentication/saml/#idp-initiated-single-sign-on-sso).
|
||||
IdP-initiated single sign on (SSO) allows the user to log in directly from the SAML identity provider (IdP). It is disabled by default for security reasons. For more information, refer to the [docs](../../setup-grafana/configure-access/configure-authentication/saml/#idp-initiated-single-sign-on-sso).
|
||||
|
||||
## Changelog
|
||||
|
||||
|
||||
@@ -211,7 +211,7 @@ For more information, refer to [Export logs of usage insights](../../setup-grafa
|
||||
|
||||
### New audit log events
|
||||
|
||||
New log out events are logged based on when a token expires or is revoked, as well as [SAML Single Logout](../../setup-grafana/configure-security/configure-authentication/saml/#single-logout). A `tokenId` field was added to all audit logs to help understand which session was logged out of.
|
||||
New log out events are logged based on when a token expires or is revoked, as well as [SAML Single Logout](../../setup-grafana/configure-access/configure-authentication/saml/#single-logout). A `tokenId` field was added to all audit logs to help understand which session was logged out of.
|
||||
|
||||
Also, a counter for audit log writing actions with status (success / failure) and logger (loki / file / console) labels was added.
|
||||
|
||||
|
||||
@@ -267,11 +267,11 @@ JWT is a new authentication option in Grafana.
|
||||
|
||||
You can now configure Grafana to accept a JWT token provided in the HTTP header.
|
||||
|
||||
[JWT authentication](../../setup-grafana/configure-security/configure-authentication/jwt/) was added and [Configuration](../../setup-grafana/configure-grafana/#authjwt) was updated as a result of this feature.
|
||||
[JWT authentication](../../setup-grafana/configure-access/configure-authentication/jwt/) was added and [Configuration](../../setup-grafana/configure-grafana/#authjwt) was updated as a result of this feature.
|
||||
|
||||
#### OAuth
|
||||
|
||||
[Generic OAuth authentication](../../setup-grafana/configure-security/configure-authentication/generic-oauth/) has been updated as a result of these changes.
|
||||
[Generic OAuth authentication](../../setup-grafana/configure-access/configure-authentication/generic-oauth/) has been updated as a result of these changes.
|
||||
|
||||
##### Added OAuth support for empty scopes
|
||||
|
||||
|
||||
@@ -130,13 +130,13 @@ Enable role-based access control by adding the term `accesscontrol` to the list
|
||||
|
||||
#### Assign SAML users different roles in different Organizations
|
||||
|
||||
You can use Grafana's SAML integration to map organizations in your SAML service to [Organizations](../../setup-grafana/configure-security/configure-authentication/saml/#configure-organization-mapping) in Grafana so that users who authenticate using SAML have the right permissions. Previously, you could only choose a single role (Viewer, Editor, or Admin) for users, which would apply to all of their Organizations. Now, you can map a given SAML user or org to different roles in different Organizations, so that, for example, they can be a Viewer in one Organization and an Admin in another.
|
||||
You can use Grafana SAML integration to map organizations in your SAML service to [Organizations](../../setup-grafana/configure-access/configure-authentication/saml/#configure-organization-mapping) in Grafana so that users who authenticate using SAML have the right permissions. Previously, you could only choose a single role (Viewer, Editor, or Admin) for users, which would apply to all of their Organizations. Now, you can map a given SAML user or org to different roles in different Organizations, so that, for example, they can be a Viewer in one Organization and an Admin in another.
|
||||
|
||||
Additionally, you can now grant multiple SAML organizations access to Grafana, using the `allowed_organizations` attribute. Previously, you could only map one.
|
||||
|
||||
{{< figure src="/static/img/docs/enterprise/8-4-SAML-auth.png" max-width="1200px" caption="Assign SAML users role" >}}
|
||||
|
||||
Learn more in our [SAML docs](../../setup-grafana/configure-security/configure-authentication/saml/).
|
||||
Learn more in our [SAML docs](../../setup-grafana/configure-access/configure-authentication/saml/).
|
||||
|
||||
### Performance improvements
|
||||
|
||||
|
||||
@@ -58,7 +58,7 @@ To see JWT URL embedding in action, see the [sample project](https://github.com/
|
||||
|
||||
You can now use GitHub OAuth2 to map users or teams to specific [Grafana organization roles](../../administration/roles-and-permissions/#organization-roles) by using `role_attribute_path` configuration option.
|
||||
Grafana will use [JMESPath](https://jmespath.org/examples.html) for path lookup and role mapping.
|
||||
For more information, see the [documentation](../../setup-grafana/configure-security/configure-authentication/github/#map-roles).
|
||||
For more information, see the [documentation](../../setup-grafana/configure-access/configure-authentication/github/#map-roles).
|
||||
|
||||
Grafana Cloud users can access this feature by [opening a support ticket in the Cloud Portal](/profile/org#support).
|
||||
|
||||
@@ -242,7 +242,7 @@ To learn more, see the [configuration documentation](../../setup-grafana/configu
|
||||
When you synchronize users from a SAML, LDAP, or OAuth provider, some user settings, such as name and email address, are synchronized from your identity provider.
|
||||
Previously, you could edit those settings in the Grafana UI, but they would revert back.
|
||||
To make user management clearer, you can now see which settings are synchronized from your identity provider, but you cannot edit those settings.
|
||||
To learn more about authentication, see the [documentation](../../setup-grafana/configure-security/configure-authentication/).
|
||||
To learn more about authentication, see the [documentation](../../setup-grafana/configure-access/configure-authentication/).
|
||||
|
||||
{{< figure src="/static/img/docs/enterprise/oauth-synced-user-9-1.png" max-width="750px" caption="Non-interactive view of a user synced via OAuth" >}}
|
||||
|
||||
|
||||
@@ -205,7 +205,7 @@ _Generally available in Grafana Enterprise, Grafana Cloud Pro, and Advanced._
|
||||
### Map a user to all organizations in Grafana
|
||||
|
||||
You can now use `*` as the Grafana organization in the mapping to add all users from a given SAML Organization to all existing Grafana organizations.
|
||||
For more information, see ["Configure SAML authentication"](/docs/grafana/next/setup-grafana/configure-security/configure-authentication/saml/#configure-organization-mapping) in the documentation.
|
||||
For more information, see ["Configure SAML authentication"](/docs/grafana/next/setup-grafana/configure-access/configure-authentication/saml/#configure-organization-mapping) in the documentation.
|
||||
|
||||
### Skip organization role sync
|
||||
|
||||
@@ -215,13 +215,13 @@ If you use a SAML identity provider to manage your users but prefer to assign ro
|
||||
|
||||
Use the `skip_org_role_sync` configuration option when configuring SAML to prevent synchronization with SAML roles and make user roles editable from within Grafana.
|
||||
|
||||
For more information, see the [SAML configuration documentation](/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/saml/).
|
||||
For more information, see the [SAML configuration documentation](/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-access/configure-authentication/saml/).
|
||||
|
||||
## Assign Server Admin permissions from Oauth
|
||||
|
||||
You can now map OAuth groups and roles to Server Admin for the GitLab, GitHub, AzureAD, Okta, and Generic OAuth integrations.
|
||||
To enable this functionality, set the `allow_assign_grafana_admin` configuration option to `true` in the desired OAuth integration section.
|
||||
For more information, see the [authentication configuration documentation](/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/) for each OAuth client.
|
||||
For more information, see the [authentication configuration documentation](/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-access/configure-authentication/) for each OAuth client.
|
||||
|
||||
## Match parameter support in prometheus labels API
|
||||
|
||||
|
||||
@@ -151,7 +151,7 @@ As part of our efforts to improve the security of Grafana, we are introducing a
|
||||
|
||||
Because this feature introduces a breaking change, it is behind the `accessTokenExpirationCheck` feature toggle and is disabled by default. Enabling this functionality without configuring refresh tokens for the specific OAuth provider will sign users out after their access token has expired, and they would need to sign in again every time.
|
||||
|
||||
Complete documentation on how to configure obtaining a refresh token can be found on the [authentication configuration page](../../setup-grafana/configure-security/configure-authentication/), in the instructions for your Oauth identity provider.
|
||||
Complete documentation on how to configure obtaining a refresh token can be found on the [authentication configuration page](../../setup-grafana/configure-access/configure-authentication/), in the instructions for your Oauth identity provider.
|
||||
|
||||
### Resolve user conflicts in Grafana's CLI
|
||||
|
||||
@@ -181,7 +181,7 @@ If you use an LDAP directory to authenticate to Grafana but prefer to assign org
|
||||
or via API, you can now skip user organization role synchronization with your LDAP
|
||||
directory.
|
||||
|
||||
Use the `skip_org_role_sync` [LDAP authentication configuration option](../../setup-grafana/configure-security/configure-authentication/ldap/#disable-org-role-synchronization)
|
||||
Use the `skip_org_role_sync` [LDAP authentication configuration option](../../setup-grafana/configure-access/configure-authentication/ldap/#disable-org-role-synchronization)
|
||||
when configuring LDAP authentication to prevent the synchronization between your LDAP groups and organization roles
|
||||
and make user roles editable manually.
|
||||
|
||||
@@ -192,7 +192,7 @@ Generally available in all editions of Grafana
|
||||
If you use Azure AD OAuth2 authentication and use `SecurityEnabled` groups that you don't want Azure to embed in the
|
||||
authentication token, you can configure Grafana to use Microsoft's Graph API instead.
|
||||
|
||||
Use the [`force_use_graph_api` configuration option](../../setup-grafana/configure-security/configure-authentication/azuread/#force-fetching-groups-from-microsoft-graph-api)
|
||||
Use the [`force_use_graph_api` configuration option](../../setup-grafana/configure-access/configure-authentication/azuread/#force-fetching-groups-from-microsoft-graph-api)
|
||||
when configuring Azure AD authentication to force Grafana to fetch groups using Graph API.
|
||||
|
||||
### RBAC: List token's permissions
|
||||
|
||||
@@ -135,7 +135,7 @@ While Grafana integrates with many different auth providers, we have received re
|
||||
|
||||
This option enables you to skip synchronization from your configured OAuth provider specifically in the auth provider section under `skip_org_role_sync`. Previously users could only do this for certain providers using the `oauth_skip_org_role_sync_update` option, but this would include all of the configured providers.
|
||||
|
||||
Learn more about Oauth in our [Oauth configuration guide](../../setup-grafana/configure-security/configure-authentication/generic-oauth/).
|
||||
Learn more about Oauth in our [Oauth configuration guide](../../setup-grafana/configure-access/configure-authentication/generic-oauth/).
|
||||
|
||||
### RBAC support for Grafana OnCall plugin
|
||||
|
||||
@@ -154,7 +154,7 @@ We've added auto-login support for SAML authentication, which you can turn on wi
|
||||
have a unified configuration style among all authentication providers. Instead of using
|
||||
`oauth_auto_login`, use the new `auto_login` option to enable automatic login for specific OAuth providers.
|
||||
|
||||
Learn more about SAML setup in our [SAML configuration guide](../../setup-grafana/configure-security/configure-authentication/saml/).
|
||||
Learn more about SAML setup in our [SAML configuration guide](../../setup-grafana/configure-access/configure-authentication/saml/).
|
||||
|
||||
## Auditing and Usage Insights: Support for Loki multi-tenancy
|
||||
|
||||
|
||||
Reference in New Issue
Block a user