Advanced Security add-on for Confluent Cloud
The Advanced Security add-on provides enterprise security capabilities for Confluent Cloud organizations. This add-on brings stronger identity, encryption, and access-control capabilities across your organization:
System for Cross-domain Identity Management (SCIM)-based user provisioning for supported single sign-on (SSO) workflows
Bring Your Own Key (BYOK) for supported resources
Higher identity and access management (IAM)-related limits for supported organization-scoped security resources
Note
The Advanced Security add-on is a Limited Availability feature in Confluent Cloud. It is fully supported and recommended for production use. Advanced Security will include additional features when generally available. Your OrganizationAdmins can enable the add-on in Confluent Cloud.
Higher limits included with the add-on
The Advanced Security add-on increases the following limits.
Resource or limit |
Default Confluent Cloud |
Advanced Security add-on |
|---|---|---|
OAuth identity pools per identity provider |
1,000 |
2,000 |
mTLS certificate identity pools per certificate authority |
1,000 |
3,000 |
Single sign-on (SSO) group mappings per organization |
100 |
1,000 |
Cross-resource RBAC role bindings to roles with Kafka permissions |
1,000 |
4,000 |
For the default limits and quota codes, see Service Quotas.
View and manage the add-on in Cloud Console
Organization administrators manage the add-on from the Organization settings page in the Confluent Cloud Console.
Important
Only OrganizationAdmins can enable the add-on. Other users can access the included security capabilities after the add-on is enabled.
To access organization-level settings in Confluent Cloud:
Open the Cloud Console.
Open the menu in the upper right.
Below your user name, click Organization settings.
If you belong to multiple organizations, select the organization you want to manage. From the organization settings page, Organization administrators can view the organization context and manage organization-level capabilities.
Enable the Advanced Security add-on.
Billing
The Advanced Security add-on uses an organization-level billing model:
Billing is based on a flat increase on your organization’s eligible pre-support Confluent Cloud infrastructure charges.
Eligible charges include Confluent Cloud infrastructure usage across products such as Kafka and Flink SQL. These charges exclude support and gateway add-ons.
Charges appear as a non-cluster-specific charge in the Cloud Console and on your invoice.
In the Confluent Cloud billing UI and on invoices, Advanced Security add-on charges
appear as a distinct non-cluster-specific charge rather than as a per-cluster
line item, shown as the advanced-security line item with product family
SecurityAddOn.
For pricing details, see Confluent Cloud pricing. For more information about Confluent Cloud billing, see Manage Billing.
Migration for existing users
If your organization was already using BYOK or higher IAM limits before the Advanced Security add-on was available, you can continue to use these features with these conditions:
If your organization already uses higher IAM limits, you keep those limits permanently.
If your organization already uses BYOK, you continue to have access to BYOK through March 15, 2027, or until the end of your commit term, whichever is greater. See your email for your applicable date.
After your applicable date, you need to enable the Advanced Security add-on or clear out your BYOK usage by deleting all resources with self-managed encryption and all your encryption keys.
For availability questions or interest in security capabilities, contact Confluent Support or your Confluent account team.