Security and account management
When you receive your Grafana Federal Cloud account, you can ship data, provision users and more. See the following topics to learn more about Federal Cloud account management.
Configure authentication and authorization
Access to your Federal Cloud instance is managed by integrating with your Single Sign On (SSO) provider.
SSO prerequisites
The following identity provider (IdP) information is required to set up authentication:
- Name and Contact Information for IdP administrator
- Email domains (for example, @mycompany.com)
- Claims for username, email, first name, last name
- Group claim
- Are you using Security Asserts Markup Language (SAML) or OpenID Connect (OIDC)?
SSO onboarding
After you have all of the required prerequisites the Grafana Federal team sets up your SSO.
If you’re using SAML, we provide you with an Entity ID and SAML Assertion Consumer Service (ACS) URL so that you can provide any relevant metadata.xml
files.
If you’re using OIDC, you need to provide us the Client ID, Client Secret, and well-known endpoint of your app/provider to complete configuration.
When SSO setup is complete, Grafana sends you the login information for your tenancy.
Role-based access control (RBAC)
RBAC provides a standardized way of granting, changing, and revoking access when it comes to viewing and modifying Grafana resources, such as dashboards, reports, and administrative settings. For more information, refer to Access Control.
Manage tenancies
Tenant management within Federal Cloud is fully handled by Grafana. When you onboard to Federal Cloud, we provide you the tenant IDs for your telemetry data. Data access within a tenant can be managed with Label Based Access Policies.
Manage stacks
Stack management within Federal Cloud is fully handled by Grafana, at this time. If you have any questions or encounter any issues related to stack management, reach out to Grafana Customer Support for assistance.
Billing
The Grafana Federal Cloud Billing/Usage dashboard is provisioned by default and can be accessed as a Grafana Dashboard in the tenancy.