About user authentication
Authentication lets you add users, assign them to roles, and give those roles access to resources as you need for your organization. The Splunk platform has several schemes that you can use for authentication. You must have an active license for authentication to work.
The Splunk platform uses the following authentication schemes:
|Scheme||Splunk platform types||Description|
|Native Splunk authentication||all||Native Splunk authentication takes precedence over any external authentication schemes. The native scheme provides the Admin, Power, and User roles by default. You can define your own roles using a list of Splunk capabilities. If you have an active license, native authentication is on by default. See Set up native Splunk authentication for more information.|
|Lightweight Directory Access Protocol (LDAP)||all||The Splunk platform supports authentication with its internal authentication services or your existing LDAP server. See Set up user authentication with LDAP for more information.|
|Security Assertion Markup Language (SAML)||all||The Splunk platform supports contacting an identity provider (IdP) that uses the SAML version 2.0 protocol and retrieving user information that can be mapped to Splunk roles. See Configure single sign-on with SAML for additional information.|
|Scripted authentication API||Splunk Enterprise||Use scripted authentication to integrate Splunk authentication with an external authentication system, such as Remote Authentication Dial-in User Service (RADIUS) or Pluggable Authentication Module (PAM). See Set up user authentication with external systems for more information.|
You can create and assign users to roles either in Splunk Web, on Splunk Cloud Platform and Splunk Enterprise, or by editing the authorize.conf configuration file on Splunk Enterprise only. For more information about roles and capabilities, read About role-based user access.
Use access control to secure Splunk data
Manage Splunk Cloud Platform users and roles
This documentation applies to the following versions of Splunk Cloud Platform™: 8.1.2103, 8.2.2105 (latest FedRAMP release), 8.2.2104, 8.2.2106, 8.2.2107, 8.2.2109