From Looker's Admin menu, you manage authentication settings to secure user access to your instance. By configuring various authentication methods, you ensure data security and compliance for your organization. You can control how users log in, including password policies, multi-factor authentication, and integration with third-party identity providers such as Google OAuth, LDAP, SAML, and OpenID Connect.
These pages appear under the Authentication section of Looker's Admin menu:
- Password Policy: Customize password complexity requirements for users on your instance.
- Two-Factor: Enable two-factor authentication and synchronize time sources.
- Google: Configure Google OAuth using the Google Cloud console and Looker Admin panel.
- LDAP: Configure Lightweight Directory Access Protocol (LDAP) settings, bindings, user attribute pairing, and role mapping.
- SAML: Configure Looker to authenticate users using Security Assertion Markup Language (SAML).
- OpenID Connect: Configure Looker to authenticate users using the OpenID Connect protocol.
- Sessions: Configure options for users to stay logged in to Looker.
- Enabling the alternate login option: Configure the option for an alternate email login when one of these authentication methods is configured: Google OAuth, LDAP, SAML, or OpenID Connect.
- Troubleshooting excessive failed login attempt emails: Configure Looker to stop sending failed login attempt emails when using third-party authentication and the Alternate Login option has been disabled.