Advanced Security add-on for Confluent Cloud

The Advanced Security add-on provides enterprise security capabilities for Confluent Cloud organizations. This add-on brings stronger identity, encryption, and access-control capabilities across your organization:

Note

The Advanced Security add-on is a Limited Availability feature in Confluent Cloud. It is fully supported and recommended for production use. Advanced Security will include additional features when generally available. Your OrganizationAdmins can enable the add-on in Confluent Cloud.

Higher limits included with the add-on

The Advanced Security add-on increases the following limits.

Resource or limit

Default Confluent Cloud

Advanced Security add-on

OAuth identity pools per identity provider

1,000

2,000

mTLS certificate identity pools per certificate authority

1,000

3,000

Single sign-on (SSO) group mappings per organization

100

1,000

Cross-resource RBAC role bindings to roles with Kafka permissions

1,000

4,000

For the default limits and quota codes, see Service Quotas.

View and manage the add-on in Cloud Console

Organization administrators manage the add-on from the Organization settings page in the Confluent Cloud Console.

Important

Only OrganizationAdmins can enable the add-on. Other users can access the included security capabilities after the add-on is enabled.

To access organization-level settings in Confluent Cloud:

  1. Open the Cloud Console.

  2. Open the menu in the upper right.

  3. Below your user name, click Organization settings.

  4. If you belong to multiple organizations, select the organization you want to manage. From the organization settings page, Organization administrators can view the organization context and manage organization-level capabilities.

  5. Enable the Advanced Security add-on.

Billing

The Advanced Security add-on uses an organization-level billing model:

  • Billing is based on a flat increase on your organization’s eligible pre-support Confluent Cloud infrastructure charges.

  • Eligible charges include Confluent Cloud infrastructure usage across products such as Kafka and Flink SQL. These charges exclude support and gateway add-ons.

  • Charges appear as a non-cluster-specific charge in the Cloud Console and on your invoice.

In the Confluent Cloud billing UI and on invoices, Advanced Security add-on charges appear as a distinct non-cluster-specific charge rather than as a per-cluster line item, shown as the advanced-security line item with product family SecurityAddOn.

For pricing details, see Confluent Cloud pricing. For more information about Confluent Cloud billing, see Manage Billing.

Migration for existing users

If your organization was already using BYOK or higher IAM limits before the Advanced Security add-on was available, you can continue to use these features with these conditions:

  • If your organization already uses higher IAM limits, you keep those limits permanently.

  • If your organization already uses BYOK, you continue to have access to BYOK through March 15, 2027, or until the end of your commit term, whichever is greater. See your email for your applicable date.

    After your applicable date, you need to enable the Advanced Security add-on or clear out your BYOK usage by deleting all resources with self-managed encryption and all your encryption keys.

For availability questions or interest in security capabilities, contact Confluent Support or your Confluent account team.