Seamless SSO in Confluent Control Center for Enhanced CFK Auth (Confluent) | Current 2025

Seamless SSO in Confluent Control Center for Enhanced CFK Auth (Confluent) | Current 2025

Source: YouTube · Confluent Developer · published Jun 9, 2025 · 35:37

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This presentation demonstrates configuring seamless SSO in Confluent Control Center using Confluent for Kubernetes (CFK) with Microsoft Azure ID as the identity provider 0:46. The goal is to simplify access management while maintaining enterprise-grade security for streaming authentication 0:46.

Key Takeaways:
• SSO provides enhanced security by mitigating risks of multiple passwords and centralizes user management through a trusted identity provider 2:13
• The architecture involves CFK (Kubernetes operator), MDS (security hub), Control Center (web UI), Azure ID (cloud identity provider), and LDAP (traditional directory) 3:27
• The authentication flow: browser → C3 backend → MDS → Azure ID → authentication → authorization code → ID token → access granted 5:01
• Azure ID setup requires: app registration, client secret creation, token configuration, endpoint capture, and redirect URI configuration 11:13
• Implementation involves deploying CFK, configuring secrets, enabling RBAC, creating role bindings, and testing the authentication flow 19:58

The demonstration shows users seamlessly accessing Control Center through SSO, highlighting the practical implementation of offloading user management to Azure AD 30:53.

Sources:

  • 0:46 Goal of simplifying access management with enterprise security
  • 2:13 Benefits of SSO implementation
  • 3:27 Architecture components explanation

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[Music] [Music] Hello everyone. Uh I am Shubam Goyel along with Vasha Sharma. I'm co-presenting on seamless SSO configuration uh in confident control center for enhanced streaming authentication with CFK. We are from Confluent. So uh we both work in a confluence support team. So now let's get back to the presentation. So in this session we'll be talking about single sign on which we are configuring in confl center and uh uh we are deploying it with via confent for Kubernetes which is CFK for uh seamless authentication and we are integrating it with Microsoft Azure in id. So the reason we are doing it is to simplify access management while maintaining enterprise grade security. So this is the agenda for the session which we'll be discussing. First we'll be laying the foundation. So this inv…