Guide
Configure LDAP Authentication and Team-Based RBAC in Portainer
Configure Portainer to use LDAP authentication and map LDAP groups to Portainer roles for team-based access control.
Published by Tasadduq Burney
11 Aug 2026, 09:15 UTC
3 min95.1K views0

Desired Outcome
Configure Portainer to authenticate users against an LDAP directory and automatically assign Portainer roles based on LDAP group membership. This enables team-based access control without manually creating users in Portainer.
Prerequisites
- Portainer server version 2.0 or newer running and reachable via its web UI.
- Administrator account in Portainer.
- Access to an LDAP server (e.g., Active Directory or OpenLDAP) with network connectivity from the Portainer host.
- LDAP bind account that has read-only permission to search users and groups.
- (Optional) LDAPS or STARTTLS configured if the LDAP server requires encrypted connections.
Procedure
- Log in to Portainer as an administrator and open the Settings menu (gear icon) → Authentication.
- Select the LDAP tab.
- Fill in the fields as shown below (replace placeholders with your actual values):
Server URL: ldap://ldap.example.com:389 Bind DN: cn=readonly,ou=serviceAccounts,dc=example,dc=com Bind Password: ******** User Search Base: ou=Users,dc=example,dc=com User Search Filter: (uid=%s) Group Search Base: ou=Groups,dc=example,dc=com Group Search Filter: (memberUid=%s) Enable TLS: false # set to true if using LDAPS or STARTTLS
Expected Checks
- Log out of Portainer, then log in using the username and password of an LDAP user that belongs to a mapped group (e.g., jdoo@example.com).
- After login, the user’s full name should appear in the top‑right corner and the team name(s) should be listed under the user’s profile (accessible via the user icon → My Profile).
- Attempt an action that is permitted by the assigned role. For a Regular user, try creating a new stack; the operation should succeed. For a Read-only user, the same attempt should be denied with a permission error.
- Review the audit log: Settings → Logs → Authentication. Look for entries showing a successful LDAP bind and a login event for the test user.
Recovery Options
If LDAP authentication causes login issues, you can revert to local Portainer authentication:
- Log in to Portainer using a local admin account (if you still have one) or use the recovery admin account created during initial setup.
- Go to Settings → Authentication → LDAP and disable the LDAP toggle or clear the Server URL field.
- Save the changes. Portainer will fall back to its internal user database.
- Optionally, re-enable LDAP after correcting the configuration (e.g., fixing the bind DN or ensuring TLS certificates are trusted).
Note: Disabling LDAP does not delete any existing local users; it only changes the source of authentication.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.