> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/admin-guide/32/authentication/openldap.md).

# OpenLDAP

Prisma Cloud can integrate with OpenLDAP, an open source implementation of the Lightweight Directory Access Protocol.

Integrating Prisma Cloud with OpenLDAP lets users access Prisma Cloud using their LDAP credentials, and lets admins define granular access control rules to Docker Engine or Kubernetes using existing LDAP identities.

With OpenLDAP integration, you can:

* Re-use the identities and groups already set up in your OpenLDAP directory.

## Integrating OpenLDAP

This procedure shows you how to integrate OpenLDAP with Prisma Cloud.

**Prerequisites:**

* You have installed OpenLDAP 2.4.44 or later. Prisma Cloud has been tested with version 2.4.44. Integration with older versions should work as well, but isn’t officially supported.

1. In your LDAP directory, create a service account that has admin privileges and that can run ldapsearch queries.

   This admin account will be used by Prisma Cloud to authenticate users in your LDAP directory. It should be able to control the entire domain, and should therefore be created under the root OU.
2. Verify that the service account can query your LDAP directory.

   Run ldapsearch, passing it the credentials for your service account, and query your directory for a user:

   ```
   $ ldapsearch -x \
     -b dc=example,dc=com \
     -D "cn=<SA-CN>,dc=example,dc=com" \
     -w <SA-PASS>
     "(cn=<some-user-cn>)"
   ```

   Where:

   | `<SA-CN>`        | Common name for the Prisma Cloud service account. |
   | ---------------- | ------------------------------------------------- |
   | `<SA-PASS>`      | Password for the Prisma Cloud service account.    |
   | `<some-user-cn>` | Common name for a user in your LDAP directory.    |
3. Open Console, and go to **Manage > Authentication > Identity Providers > LDAP**.
4. Set **Integrate LDAP users and groups with Prisma Cloud** to **Enabled**.
5. For **Authentication type**, select **OpenLDAP**.
6. For **Path to LDAP service**, enter the LDAP server and port number in the following format:

   For secure connections over TLS: `ldaps://<server-dns>:<port-number>`.

   For insecure connections: `ldap://<server-dns>:<port-number>`
7. For **Search base**, enter the base DN for your users and groups.
8. (OPTIONAL) For **User identifier**, specify an attribute to be used to match users.

   For example, enter uid to match users based on their user IDs.
9. For **Service account UPN**, enter the DN for your Prisma Cloud service account.
10. For **Service account password**, enter the password for the Prisma Cloud service account.
11. For **CA certificate**, provide the CA certificate used to sign the LDAPS certificate on the server.

    Prisma Cloud uses the CA certificate to validate the LDAPS certificate and prevent man-in-the-middle attacks. If you are using an insecure connection or do not wish to validate the LDAPS certificate, leave this field blank.
12. Click **Save**.

    Console verifies all your parameters with the server. If a connection cannot be established, an error message is shown and no parameters are saved.

## Verifying integration with OpenLDAP

Verify the integration with OpenLDAP.

1. Open Console.
2. If you are logged into Console, log out.

   <figure><img src="/files/449r8UbXEuIB3gdanmIL" alt="logout"><figcaption></figcaption></figure>
3. Log in to Console using the credentials of an existing OpenLDAP user.

   If the log in is successful, you are directed to the view appropriate for the user’s role.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/admin-guide/32/authentication/openldap.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
