<a id="advanced-security-add-on"></a>

# Advanced Security add-on for Confluent Cloud

The Advanced Security add-on provides enterprise security capabilities for
Confluent Cloud organizations. This add-on brings stronger identity, encryption, and
access-control capabilities across your organization:

- [System for Cross-domain Identity Management](authenticate/user-identities/user-idps/sso/scim.md#scim-user-provisioning) (SCIM)-based user provisioning for supported single
  sign-on (SSO) workflows
- [Bring Your Own Key (BYOK)](encrypt/byok/overview.md#byok-encrypted-clusters) for supported
  resources
- Higher identity and access management (IAM)-related limits for supported
  organization-scoped security resources

#### NOTE
The Advanced Security add-on is a Limited Availability
feature in Confluent Cloud. It is fully supported and recommended
for production use. Advanced Security will include
additional features when generally available. Your
[OrganizationAdmins](access-control/rbac/predefined-rbac-roles.md#organizationadmin-role)
can enable the add-on in Confluent Cloud.

## Higher limits included with the add-on

The Advanced Security add-on increases the following limits.

| Resource or limit                                                 |   Default Confluent Cloud |   Advanced Security add-on |
|-------------------------------------------------------------------|---------------------------|----------------------------|
| OAuth identity pools per identity provider                        |                     1,000 |                      2,000 |
| mTLS certificate identity pools per certificate authority         |                     1,000 |                      3,000 |
| Single sign-on (SSO) group mappings per organization              |                       100 |                      1,000 |
| Cross-resource RBAC role bindings to roles with Kafka permissions |                     1,000 |                      4,000 |

For the default limits and quota codes, see [Service Quotas](../quotas/service-quotas.md#service-quotas).

## View and manage the add-on in Cloud Console

Organization administrators manage the add-on from the **Organization settings** page
in the Confluent Cloud Console.

#### IMPORTANT
Only [OrganizationAdmins](access-control/rbac/predefined-rbac-roles.md#organizationadmin-role) can enable the add-on.
Other users can access the included security capabilities after the add-on is enabled.

To access organization-level settings in Confluent Cloud:

1. Open the Cloud Console.
2. Open the menu in the upper right.
3. Below your user name, click **Organization settings**.
4. If you belong to multiple organizations, select the organization you want to manage.
   From the organization settings page, [Organization administrators](access-control/rbac/predefined-rbac-roles.md#organizationadmin-role) can view the organization context and manage
   organization-level capabilities.
5. Enable the Advanced Security add-on.

<a id="advanced-security-billing"></a>

## Billing

The Advanced Security add-on uses an organization-level billing model:

- Billing is based on a flat increase on your organization’s eligible pre-support
  Confluent Cloud infrastructure charges.
- Eligible charges include Confluent Cloud infrastructure usage across products such as
  Kafka and Flink SQL. These charges exclude support and gateway add-ons.
- Charges appear as a non-cluster-specific charge in the Cloud Console
  and on your invoice.

In the Confluent Cloud billing UI and on invoices, Advanced Security add-on charges
appear as a distinct non-cluster-specific charge rather than as a per-cluster
line item, shown as the `advanced-security` line item with product family
`SecurityAddOn`.

For pricing details, see [Confluent Cloud pricing](https://www.confluent.io/confluent-cloud/pricing/). For more information about
Confluent Cloud billing, see [Manage Billing](../billing/overview.md#cloud-billing).

<a id="advanced-security-migration"></a>

## Migration for existing users

If your organization was already using BYOK or higher IAM limits before the
Advanced Security add-on was available, you can continue to use these features
with these conditions:

- If your organization already uses higher IAM limits, you keep those limits
  permanently.
- If your organization already uses BYOK, you continue to have access to BYOK
  through March 15, 2027, or until the end of your commit term, whichever is greater.
  See your email for your applicable date.

  After your applicable date, you need to enable the Advanced Security
  add-on or clear out your BYOK usage by deleting all resources with
  self-managed encryption and all your encryption keys.

For availability questions or interest in security capabilities, contact
Confluent Support or your Confluent account team.

## Related content

- [Manage security on Confluent Cloud](overview.md#manage-security-overview)
- [Protect data at rest using self-managed encryption keys](encrypt/byok/overview.md#byok-encrypted-clusters)
- [Use single sign-on (SSO) for authentication](authenticate/user-identities/user-idps/sso/enable-sso.md#enable-sso)
- [Understand service quotas for Confluent Cloud](../quotas/service-quotas.md#service-quotas)
- [Manage Billing in Confluent Cloud](../billing/overview.md#cloud-billing)
