> For the complete documentation index, see [llms.txt](https://academy.pentaho.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://academy.pentaho.com/administrator-path-sandbox/administrator/level-2-associate.md).

# Level 2 — Associate

Builds on Level 1 with directory-based authentication. 16 lessons across 4 modules, ending in a capstone project connecting a Pentaho Server to LDAP or Active Directory and troubleshooting a broken lo

{% hint style="warning" %}
**🧪 SANDBOX — draft content**, sourced from docs.pentaho.com's "Secure the Pentaho system" section and the "Support & Troubleshooting" course. Lesson times below are estimates — REPLACE-ME throughout.
{% endhint %}

Level 1 gets a server running securely. Level 2 connects it to the directory your organization already uses for accounts and groups — LDAP and Microsoft Active Directory are Pentaho's two out-of-the-box (no plugin, no custom code) authentication providers — then covers what to do when a login stops working.

{% columns %}
{% column %}

<p align="center"><i class="fa-file-lines" style="color:green;">:file-lines:</i><br><strong>16 lessons</strong><br><em>across 4 modules</em></p>
{% endcolumn %}

{% column %}

<p align="center"><i class="fa-flask" style="color:orange;">:flask:</i><br><strong>9 workshops</strong><br><em>hands-on labs</em></p>
{% endcolumn %}

{% column %}

<p align="center"><i class="fa-clock" style="color:cyan;">:clock:</i><br><strong>~3h 20m</strong><br><em>REPLACE-ME — estimated</em></p>
{% endcolumn %}
{% endcolumns %}

{% hint style="success" icon="cloud-arrow-up" %}
Every workshop is hands-on and runs on Pentaho's hosting platform. The Lab Guide is embedded in each lab and loads automatically when you open it — nothing to install.
{% endhint %}

***

<h3 align="center">Before you start</h3>

{% columns %}
{% column %}
{% hint style="success" icon="circle-check" %}
**What you'll need**

Level 1 course completion, or equivalent experience hardening and configuring a Pentaho Server. Access to — or familiarity with — an LDAP or Active Directory environment will make the labs more concrete, but a demo directory is provided.
{% endhint %}
{% endcolumn %}

{% column %}
{% hint style="info" icon="tag" %}
**Built against**

REPLACE-ME — confirm target Pentaho version for this level (other paths are built against 11.0.0.3-310).
{% endhint %}
{% endcolumn %}
{% endcolumns %}

***

{% hint style="info" icon="trophy" %}

#### What you'll build

The level ends in a capstone project: connect your Level 1 server to an LDAP or Active Directory directory, map users and groups to Pentaho roles, harden the security configuration around it, and diagnose a deliberately broken login using the logging techniques from Module 4.
{% endhint %}

***

<h3 align="center">What you'll learn</h3>

{% columns %}
{% column %}

* The security configuration surface underneath any directory provider — ACLs, URL credentials, disabling security, folder visibility
* Configure Pentaho against LDAP: connection settings, bind credentials, user/role mapping
  {% endcolumn %}

{% column %}

* Configure Pentaho against Microsoft Active Directory, including AD-specific connection quirks
* Diagnose authentication failures using Spring Security debug logging
  {% endcolumn %}
  {% endcolumns %}

***

<h3 align="center">Course Outline</h3>

<p align="center"><i class="fa-file-lines" style="color:green;">:file-lines:</i> reading · <i class="fa-flask" style="color:orange;">:flask:</i> hands-on workshop</p>

{% hint style="info" icon="circle-info" %}
Full lessons unlock once you're enrolled — this is the outline only. All times are estimates — REPLACE-ME.
{% endhint %}

<table><thead><tr><th width="306">Module</th><th width="114" align="center">Reading</th><th width="139" align="center">Workshops</th><th width="100" align="right">Time</th><th>Videos</th></tr></thead><tbody><tr><td>Pentaho Server Security Fundamentals</td><td align="center">3</td><td align="center">3</td><td align="right">~1h 05m</td><td></td></tr><tr><td>LDAP Integration</td><td align="center">1</td><td align="center">2</td><td align="right">~45m</td><td></td></tr><tr><td>Microsoft Active Directory (MSAD) Integration</td><td align="center">1</td><td align="center">2</td><td align="right">~45m</td><td></td></tr><tr><td>Troubleshooting Directory Authentication</td><td align="center">2</td><td align="center">2</td><td align="right">~45m</td><td></td></tr><tr><td>Capstone Project</td><td align="center">—</td><td align="center">1 project</td><td align="right">—</td><td></td></tr><tr><td><strong>Total</strong></td><td align="center"><strong>7</strong></td><td align="center"><strong>9</strong></td><td align="right"><strong>~3h 20m</strong></td><td></td></tr></tbody></table>

{% stepper %}
{% step %}

### <i class="fa-lock" style="color:blue;">:lock:</i> Pentaho Server Security Fundamentals

`3 reading · 3 workshops · ~1h 05m`

The security configuration surface you're working within before swapping in a directory provider.

<details>

<summary>See the full breakdown</summary>

<table><thead><tr><th width="78"></th><th>Lesson</th><th width="90">Time</th></tr></thead><tbody><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Overview</td><td>~10m</td></tr><tr><td></td><td></td><td></td></tr><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>User Security Overview — how Pentaho's security model maps onto an external provider</td><td>~10m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Restrict or Share Files and Folders</td><td>~15m</td></tr><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Passing Authentication Credentials in URL Parameters</td><td>~10m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Remove Pentaho Server Security</td><td>~10m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Hiding User Folders in PUC and PDI</td><td>~10m</td></tr></tbody></table>

</details>
{% endstep %}

{% step %}

### <i class="fa-diagram-project" style="color:blue;">:diagram-project:</i> LDAP Integration

`1 reading · 2 workshops · ~45m`

Point Pentaho at an LDAP directory and map its users and groups to Pentaho roles.

<details>

<summary>See the full breakdown</summary>

<table><thead><tr><th width="78"></th><th>Lesson</th><th width="90">Time</th></tr></thead><tbody><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Overview</td><td>~10m</td></tr><tr><td></td><td></td><td></td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Configure LDAP Security — connection settings, bind credentials, testing the connection</td><td>~20m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>User &#x26; Role Mapping (LDAP)</td><td>~15m</td></tr></tbody></table>

</details>
{% endstep %}

{% step %}

### <i class="fa-windows" style="color:blue;">:windows:</i> Microsoft Active Directory (MSAD) Integration

`1 reading · 2 workshops · ~45m`

Configure Pentaho against Active Directory as the LDAP-compatible directory it is, including AD-specific connection quirks.

<details>

<summary>See the full breakdown</summary>

<table><thead><tr><th width="78"></th><th>Lesson</th><th width="90">Time</th></tr></thead><tbody><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Overview</td><td>~10m</td></tr><tr><td></td><td></td><td></td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Configure MSAD Security</td><td>~20m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>User &#x26; Role Mapping (MSAD) — users, security groups and OUs</td><td>~15m</td></tr></tbody></table>

</details>

{% hint style="warning" icon="circle-question" %}
**REPLACE-ME** — confirm whether the LDAP and MSAD modules should be combined into one "Directory-Based Security" module given how much configuration they share, or kept separate as above so learners can jump straight to whichever directory they use.
{% endhint %}
{% endstep %}

{% step %}

### <i class="fa-magnifying-glass" style="color:blue;">:magnifying-glass:</i> Troubleshooting Directory Authentication

`2 reading · 2 workshops · ~45m`

When a login fails against LDAP, AD or JDBC security, the fastest path to an answer is the server logs — not guesswork.

<details>

<summary>See the full breakdown</summary>

<table><thead><tr><th width="78"></th><th>Lesson</th><th width="90">Time</th></tr></thead><tbody><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Overview</td><td>~10m</td></tr><tr><td></td><td></td><td></td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Enable Spring Security Debug Logging</td><td>~15m</td></tr><tr><td><i class="fa-file-lines" style="color:green;">:file-lines:</i></td><td>Reading the Failure — "bad credentials" vs. "user not found"</td><td>~10m</td></tr><tr><td><i class="fa-flask" style="color:orange;">:flask:</i></td><td>Confirm a Successful Login — reading granted roles/authorities in the log</td><td>~10m</td></tr></tbody></table>

</details>

{% hint style="warning" icon="circle-question" %}
**REPLACE-ME** — sourced from the "Support & Troubleshooting" course's security logging demo, which references `applicationContext-spring-security-jackrabbit.xml`. Confirm this file path and the DAO provider bean name are still current before writing the hands-on steps.
{% endhint %}
{% endstep %}

{% step %}

### <i class="fa-trophy" style="color:red;">:trophy:</i> Capstone Project

`1 project`

Bring it all together: connect your Level 1 server to a directory, map roles, harden the configuration around it, and prove you can find a login problem from the logs alone.

<details>

<summary>See the project brief</summary>

The client from your Level 1 capstone is rolling out to the whole company and wants single-directory login — no more locally managed Pentaho users. Connect the server to LDAP or Active Directory (your choice), map their groups to the right Pentaho roles, lock down the security fundamentals from Module 1, and then diagnose and fix a login issue planted in the lab using nothing but the server logs.

</details>
{% endstep %}
{% endstepper %}

***

{% columns %}
{% column %}
{% hint style="warning" icon="file-certificate" %}
**Course completion**

Course completion applies to Levels 1 and 2. Finish the lessons and workshops and pass the exam embedded in the guide, and you'll automatically be able to download a certificate of Course Completion. It states your name, the course, and the Pentaho version you studied against. Unlike certification, this exam is self-paced and not proctored.
{% endhint %}
{% endcolumn %}

{% column %}
{% hint style="warning" icon="award" %}
**Certification**

Certification is only available at Level 3 — Professional — not this level. It's a separate, proctored credential that organisations look for when engaging Pentaho consultants: the more advanced courses and the Speciality course feed into it, and the exam itself is proctored — unlike the embedded exam for course completion.
{% endhint %}
{% endcolumn %}
{% endcolumns %}

***

<p align="center"><a href="/administrator-path-sandbox/administrator.md" class="button secondary" data-icon="arrow-left">Back to Administrator path</a></p>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://academy.pentaho.com/administrator-path-sandbox/administrator/level-2-associate.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
