Connecting LDAP to Grafana lets you centralize user authentication and control access with your enterprise directory. This integration allows developers and identity engineers to align dashboard permissions and roles in Grafana with the authoritative structure of systems like Active Directory or OpenLDAP. This guide explains the setup process, security decisions, mapping strategies, and real-world troubleshooting techniques using both file-based and UI-based workflows.
Link to Why Connect LDAP to Grafana?Why Connect LDAP to Grafana?
LDAP integration enables Grafana to:
- Authenticate users using your directory’s records (not just local accounts).
- Map group memberships or organizational units in LDAP to specific Grafana roles.
- Automate user lifecycle management—provisioning, deprovisioning, and access right changes—all following directory policies.
Use LDAP-backed authentication when you want centralized user management, automatic group-to-role privileges, and stricter lifecycle control, as opposed to manual local account management.
Link to LDAP Integration PrerequisitesLDAP Integration Prerequisites
Before integrating LDAP with Grafana, you’ll need:
- Directory type and connection details: Know your LDAP server addresses, port(s), and schema layout. Both Active Directory, OpenLDAP, and other LDAPv3-compliant servers are supported.
- Bind account information: Typically, a non-privileged LDAP "bind" account is used so Grafana can search for users and groups. This account should have read-only access over the relevant OUs. Note: A
bind_passwordis not always mandatory—certain directory types like Active Directory can be configured for user bind (for example, by makingbind_dn = 'DOMAIN\\%s'), or even, in rare cases, anonymous binding. However, anonymous or unauthenticated binds are discouraged due to security risks and lack of auditability. Always prefer a dedicated, least-privilege, credentialed bind user unless you have reviewed your directory’s security implications. - Directory structure awareness: Determine user and group base DNs and suitable search filters (e.g.,
CN=Users,DC=example,DC=com). - Login attribute knowledge: Know which unique attribute (username, email, or custom field) your users employ to log in; this sharpens your
search_filter. - Firewall/network readiness: Ensure Grafana can access the LDAP server securely (ports 389 for LDAP/StartTLS, 636 for LDAPS).
Link to Connecting Grafana to LDAP: File-Based and UI ApproachesConnecting Grafana to LDAP: File-Based and UI Approaches
Grafana supports two integration models for LDAP:
Link to File-Based Configuration (ldap.toml)File-Based Configuration (ldap.toml)
- Where: The
ldap.tomlfile resides in Grafana’s configuration directory. - Appropriate for: Automated environments, source-controlled deployments, scenarios with complex or multiple directory integrations.
- Features: Every LDAP option is configurable; supports several directories/domains using multiple
[[servers]]blocks. - Persistence: Durable across upgrades if managed via automation.
Link to UI-Based ConfigurationUI-Based Configuration
- Where: Available in Grafana Enterprise and Grafana Cloud editions.
- Appropriate for: Teams preferring graphical configuration or initial setup without direct file edits.
- Features: Walks you through most required LDAP fields via forms. Advanced options or support for multiple directories may still require manual edits in
ldap.toml. - Persistence: Settings live in Grafana’s database, update instantly, but should be exported for disaster recovery documentation.
How to choose: Both approaches control the same underlying mechanisms. Prefer ldap.toml when versioning or complex mapping is needed; use the UI for simplicity or less technical administration.
Link to LDAP Connection Security: LDAPS, StartTLS, and CertificatesLDAP Connection Security: LDAPS, StartTLS, and Certificates
Protect all credentials and user data as they traverse the network between Grafana and your LDAP server:
Link to LDAPS and StartTLS: Key Distinctions and SecurityLDAPS and StartTLS: Key Distinctions and Security
- LDAPS: Runs LDAP directly over SSL/TLS (typically port 636). The connection is encrypted from the outset.
- StartTLS: Begins as plaintext on standard LDAP port 389, then upgrades to secure TLS with a StartTLS command after connection.
Warning: LDAPS and StartTLS are not identical or fully interchangeable. They use different negotiation methods, require different ports, and may vary in certificate handling at the server or firewall level. Do not assume a configuration for one will automatically work with the other.
- Always prefer encrypted connections in production—never use plaintext LDAP for sensitive authentication.
- In configuration, use
use_ssl = truefor LDAPS orstart_tls = truefor StartTLS, and ensure the correct port is in use (636 or 389, respectively). - Certificate handling: Never disable SSL verification (
ssl_skip_verify = true) in production. This setting skips validation of the LDAP server's certificate and exposes login credentials to potential interception or man-in-the-middle attacks. If your environment uses a custom or private CA, specifyroot_ca_certto establish trust.
Development shortcuts—like using insecure connections or disabling certificate checks—must not be carried into deployed environments.
Link to Key Configuration Parameters ExplainedKey Configuration Parameters Explained
Thorough understanding of ldap.toml (or the UI's fields) is critical:
Link to Example — Connection and Search BasicsExample — Connection and Search Basics
[[servers]]
host = "ad.example.com"
port = 636
use_ssl = true
bind_dn = "CN=readonly,CN=Users,DC=example,DC=com"
bind_password = "ENV_VAR_GRAFANA_LDAP_PASSWORD"
search_base_dns = ["CN=Users,DC=example,DC=com"]
search_filter = "(sAMAccountName=%s)"
[servers.attributes]
name = "givenName"
surname = "sn"
username = "sAMAccountName"
email = "mail"
- host/port: Target LDAP server and port (636 for LDAPS, 389 for StartTLS).
- use_ssl / start_tls: Boolean flags for connection security (never both true).
- bind_dn / bind_password: Credentials for the directory bind user (may reference environment variables for security).
- search_base_dns: Array of DNs to initiate search—for example, where users reside.
- search_filter: The LDAP search pattern;
%sis replaced with the login value entered in Grafana.
Link to Group MappingGroup Mapping
User mapping (locating and authenticating who a user is) and group mapping (assigning roles or teams based on groups) are distinct steps. Correct configuration requires attention to both processes.
Link to Example — Complete [[servers.group_mappings]] BlockExample — Complete [[servers.group_mappings]] Block
[[servers.group_mappings]]
group_dn = "CN=GrafanaAdmins,OU=Groups,DC=example,DC=com"
org_role = "Admin"
[[servers.group_mappings]]
group_dn = "CN=GrafanaEditors,OU=Groups,DC=example,DC=com"
org_role = "Editor"
[[servers.group_mappings]]
group_dn = "*"
org_role = "Viewer"
- The first matching
group_dnassigns the role; mappings are prioritized in order. - You may define multiple mapped groups for tiered permissions.
- For directories lacking the
memberOfattribute, usegroup_search_filterand configure searches by user membership.
Link to Multiple Directory SupportMultiple Directory Support
Grafana allows several [[servers]] blocks inside ldap.toml, so you can enable login from multiple independent directories or domains within a single Grafana deployment.
Link to User and Group Mapping StrategiesUser and Group Mapping Strategies
Link to User Search FiltersUser Search Filters
Adjust search_filter to match how users identify themselves:
- Username (Active Directory):
(sAMAccountName=%s) - Username (OpenLDAP):
(uid=%s) - Support login via email or username:
(|(sAMAccountName=%s)(mail=%s)) - Non-standard schemas: Adjust filter to target your user attribute (e.g.,
(customAttribute=%s)).
Tip: Use %s in the filter—Grafana replaces it with the user's login value.
Link to Group Mapping MethodsGroup Mapping Methods
- Direct mapping: Reference the exact group DN. For example,
group_dn = "CN=GrafanaEditors,OU=Groups,DC=example,DC=com". - Team/role sync: Use multiple group mappings to assign various roles; mapping order decides which role applies.
- Non-standard group structures: If your directory doesn't populate
memberOf, specifygroup_search_filterand group search attributes directly.
Best practices:
- Structure directory groups to match Grafana team needs precisely.
- Avoid wildcard group searches unless necessary—this prevents unauthorized privilege escalation.
Link to Testing and Troubleshooting LDAP AuthenticationTesting and Troubleshooting LDAP Authentication
Link to Enabling Debug LoggingEnabling Debug Logging
Adjust grafana.ini:
[log]
filters = ldap:debug
This will output verbose LDAP operations—connection, bind, search, and mapping attempts—to the Grafana logs.
Link to Validating Directory ConnectivityValidating Directory Connectivity
Tools like ldapsearch help confirm connection and filter correctness outside of Grafana. For example:
ldapsearch -H ldaps://ad.example.com:636 -D "CN=readonly,CN=Users,DC=example,DC=com" -W -b "CN=Users,DC=example,DC=com" "(sAMAccountName=jdoe)"
- Replace values as required for your directory and SSL/TLS needs.
- If results are empty or you get errors, check your credentials, ports, and search base/filter before troubleshooting Grafana.
Link to Common Issues and ResolutionsCommon Issues and Resolutions
- Cannot connect to LDAP: Check network reachability and ensure SSL/TLS is correctly configured; watch for certificate errors.
- Bind failures: Verify
bind_dnand password (test directly withldapsearchor similar tools). - User not found: Re-examine
search_base_dnsandsearch_filter—test queries with directory tools. - Incorrect group mapping: Check syntax of
group_dnand the existence ofmemberOf; validate group searches as needed. - Unexpected role assignments: Remember, only the first matching
group_mappingapplies; check mapping order and filters.
Careful inspection of Grafana logs with debug enabled will indicate the failure phase: connection, bind, user search, group mapping, or attribute extraction.
Link to Security Best Practices and Maintenance TipsSecurity Best Practices and Maintenance Tips
- Least-privilege binds: Ensure the bind user can only read necessary user and group OUs.
- Secret management: Use environment variables for
bind_passwordand rotate credentials periodically. Never hard-code sensitive credentials in deployment files. - Certificate validation: Do not skip SSL or TLS verification in production environments.
- Monitoring/audit: Review authentication logs for failed login attempts or unusual patterns. Integrate with your organization's monitoring to alert on suspicious activity.
Regularly review LDAP and Grafana configurations, especially when directory membership or structure changes.
Link to LDAP Authentication vs Other Methods in GrafanaLDAP Authentication vs Other Methods in Grafana
Grafana’s authentication options include:
- LDAP: Tightly binds access and roles to your directory structure. Best when granular group-to-role control is needed and direct SSO is not available.
- SSO (SAML/OAuth): Supports full single sign-on across SaaS/cloud applications, usually more seamless for end-users.
- Hybrid: You may enable both LDAP and other authentication providers in parallel, and, with multiple
[[servers]]blocks, Grafana can authenticate users from several domains or directories in the same instance.
LDAP is preferable for highly controlled environments where group and role mapping must mirror your directory with precision and when SSO isn't required or available.
Link to References and Further ReadingReferences and Further Reading
- Canonical ldap.toml example (all supported options and syntax): github.com/grafana/grafana/blob/main/conf/ldap.toml
- Comprehensive discussion on directory account and password requirements for AD: github.com/grafana/grafana/issues/10040
- LDAP protocol specification (RFC 4511): docs.ldap.com/ldap-sdk/docs/specs/rfc4511.txt