Getting Started with Identity and Access Management
Control who can access your LogScale environment and what they can do
Understanding the Basics
Start here if you are new to identity management. Learn what authentication and authorization are, understand RBAC components, and explore identity provider options. This foundation prepares you for configuration.
- Authentication vs Authorization
- Identity Providers and SSO
- RBAC Building Blocks
- Permission Scopes
Setting Up Your Environment
Ready to configure? Set up your identity provider (SAML or LDAP), create roles and groups, configure group synchronization, and establish the foundation for user access.
- Identity Provider Setup
- Creating Roles and Groups
- Group Synchronization
- User Provisioning
Applying Access Controls
Now that authentication and basic RBAC are configured, apply permissions to real resources. Control access to repositories, share dashboards and queries, and test user access.
- Repository Permissions
- Asset Sharing
- Testing User Access
Optimization and Troubleshooting
Troubleshoot access issues, and optimize your identity and access management at scale.
- Troubleshooting
- Performance Optimization
Phase 1: Understanding the Basics
Build a strong foundation in authentication and authorization concepts before configuring your environment. Understanding these fundamentals makes implementation intuitive and secure.
Authentication vs Authorization
Understand the difference between who you are and what you can do
Identity Providers and SSO
Learn how external identity providers integrate with LogScale
Planning Authentication
guideintermediateUnderstand how LogScale authenticates users. Learn about local authentication, SAML, LDAP, and OAuth options. Plan which identity provider fits your organization.
SAML Overview
conceptintermediateLearn how SAML single sign-on works, understand SAML assertions and attributes, and determine if SAML fits your organization.
LDAP Overview
conceptintermediateLearn how LDAP authentication works, understand directory services integration, and determine if LDAP fits your organization.
RBAC Building Blocks
Understand users, groups, roles, and permissions
The Building Blocks
guideintermediateUnderstand Users (individual people), Groups (collections of users), Roles (named sets of permissions), and Permissions (specific capabilities).
Permission Strategy Patterns
guideintermediateApply the principle of least privilege, choose group-based versus direct assignment, establish role naming conventions, and plan for multi-tenant scenarios.
Permission Scopes and Hierarchy
Learn the four permission levels and how they work together
Organization and Cluster Permissions
guideintermediateLearn how organization-level and cluster-level permissions work. Cluster permissions apply only to self-hosted environments.
Repository and View Permissions
guideintermediateUnderstand repository and view permissions. Learn about the four permission levels and how permissions are NOT inherited between scopes.
Asset Permissions Overview
conceptintermediateLearn how permissions control access to dashboards, saved queries, alerts, actions, and scheduled reports.
Phase 2: Setting Up Your Environment
Configure authentication and create the foundational RBAC components. This phase establishes how users log in and sets up the roles and groups you need.
Choosing and Configuring Your Identity Provider
Set up authentication for single sign-on
Configure SAML
guideintermediateStep-by-step instructions for configuring SAML authentication on self-hosted LogScale. Connect your SAML identity provider, configure metadata, set up attribute mapping, and test SSO login.
Configure LDAP
guideintermediateStep-by-step instructions for configuring LDAP authentication. Connect to your LDAP directory, configure bind credentials, set up user search filters, and test authentication.
Configure OpenID Connect
guideintermediateStep-by-step instructions for configuring OpenID Connect (OIDC) authentication.
Configure OAuth
guideintermediateStep-by-step instructions for configuring OAuth authentication.
Creating Roles
Build custom and default roles with specific permissions
Manage Roles
guideintermediateCreate custom roles, assign granular permissions, and understand default roles (Reader, Admin, Member, Deleter).
Create a New Role
guideintermediateStep-by-step instructions for creating a custom role with specific permissions.
Edit Role Permissions
guideintermediateModify permissions for existing roles to match your organization's needs.
Default Roles
guideintermediateLearn about Reader, Admin, Member, and Deleter roles and their predefined permissions.
Creating Groups
Set up groups for organizing users and connecting to identity providers
Configuring Group Synchronization
Automate group membership based on identity provider groups
Group Synchronization
guideintermediateAutomate group membership based on identity provider group membership. Configure one-to-many group mapping strategies for SAML and LDAP.
SAML Group Mapping
guideintermediateConfigure SAML group attributes and map identity provider groups to LogScale groups.
OAuth Role to LogScale Groups Mapping
guideintermediateConfigure OAuth role mapping to map identity provider roles to LogScale groups
User Provisioning Options
Configure how users are created and managed
Phase 3: Applying Access Controls
Apply the authentication and RBAC components you configured to real resources. Control who can access repositories, views, and assets.
Assigning Roles to Groups
Connect roles to groups with default permissions and exceptions
Assign Roles to Groups
guideintermediateSet default roles for group members, configure query prefixes to filter data automatically, and create repository exceptions.
Default Role for Groups
guideintermediateAssign a default role that applies to all members of a group.
Query Prefix
guideintermediateAutomatically filter queries for group members to restrict data access.
Repository Exceptions
guideintermediateAssign different roles to a group in specific repositories.
Add Users to Groups
guideintermediateManually add users to groups to grant them the group's permissions.
Assigning Roles to Users
Directly assign roles to individual users when needed
Controlling Repository and View Access
Grant access to data repositories and views
Repository and View Permissions
guideintermediateGrant groups, roles, and users access to specific repositories. Understand different repository permission types and set up views.
Organization Permissions
guideintermediateManage who can manage users and groups, change organization settings, and manage identity providers.
Cluster Permissions
guideintermediateFor self-hosted: Manage cluster-level permissions for system administration tasks.
Sharing Assets
Grant access to dashboards, saved queries, alerts, and actions
Asset Sharing Permissions
guideintermediateControl who can view, edit, and delete dashboards. Manage saved query permissions, alert and action permissions, and scheduled report access control.
Grant User Access to Assets
guideintermediateShare specific assets (dashboards, queries, alerts) with individual users.
Grant Group Access to Assets
guideintermediateShare specific assets with groups to simplify permission management.
Testing and Validating User Access
Verify authentication and permissions work as expected
View Aggregate Permissions
guideintermediateView all permissions a user has across multiple roles to understand their total access level. Use this to verify users have the expected access. Essential for complex role hierarchies.
Verify Group Memberships
guideintermediateCheck that users appear in the correct groups after SSO login. Understand how group membership works with manual assignment and identity provider synchronization.
Test SSO Login
guideintermediateVerify users can log in through your identity provider. Test authentication flow, verify user attributes are mapped correctly, and confirm group sync works.
Phase 4: Optimization and Troubleshooting
Refine your identity and access management implementation with advanced patterns, security hardening, and troubleshooting capabilities.
Troubleshooting
Diagnose and fix login and SSO problems, and understand access denied errors
Troubleshoot Authentication
troubleshootingintermediateDebug common authentication issues: SAML assertion errors, LDAP bind failures, attribute mapping problems, and SSO redirect loops.
Manage User Roles
guideintermediateView and edit roles assigned directly to individual users. Assign or remove user-specific roles to resolve access issues.
Permission Reference Guides
Complete reference documentation for all permissions
Permissions by Functionality
guideintermediateFind which permissions are needed for specific LogScale features and functionality. Organized by what you want to do.
Permissions by Name
guideintermediateAlphabetical reference of all available permissions and what they control. Organized by permission name.