MongoDB
Atlas For Your Enterprise
Ryan K. Vander Zanden, Sr. Solutions Architect, MongoDB
Atlas For Enterprise
NO EXCUSES
Atlas For Enterprise
Welcome
To
Atlas!
Active Directory
LDAPS
Ryan K Vander Zanden
(RVZ)
Sr. Solution Architect
MongoDB
Let’s Get To Know Each Other
Let’s Get To Know Each Other
CTO
January 2011 - Present
MongoDB Atlas Customer
March 2017 - Present
Let’s Get To Know Each Other
CTO……….
January 2011 - Present
MongoDB Atlas Customer
March 2017 - Present
Let’s Get To Know Each Other
CTO……….
Architect, DBA, Sys Admin, Developer, QA, Project Manager
January 2011 - Present
MongoDB Atlas Customer
March 2017 - Present
Let’s Get To Know Each Other
CTO……….
Architect, DBA, Sys Admin, Developer, QA, Project Manager
+ everything else that involves a computer
January 2011 - Present
MongoDB Atlas Customer
March 2017 - Present
Let’s Get To Know Each Other
Raise your hand if...
you know what MongoDB is
Let’s Get To Know Each Other
Raise your hand if...
you have used MongoDB
Let’s Get To Know Each Other
Raise your hand if...
you know what MongoDB Atlas is
Let’s Get To Know Each Other
Raise your hand if...
you have used MongoDB Atlas
What is Atlas?
1 2
and...
What is Atlas? Secure
Scalable
Available
Free-tierable
Pay For What You Use
Elastic
Database Service
Automated Operations
Performance Visibility
Continuous Backups
3
Why Move To Atlas?
Cloud Perks!
Confirmed Safe
By Regulators!
Cloud Computing
Why Move To Atlas?
IT
Why Move To Atlas?
IS
Why Move To Atlas?
SO
Why Move To Atlas?
EASY!
Excuses, Excuses...
! X NO
...and we’re just getting started!
Introducing Atlas For Enterprise
Active Directory
LDAPS
BYO Active Directory via LDAPS
BYO Active Directory via LDAPS
Lightweight Directory Access Protocol
(Secure)
BYO Active Directory via LDAPS
W
h
y
?
Single Sign-On (SSO)
Security Administration
Password Controls
BYO Active Directory via LDAPS
Configure
Configure
Configure
Configure
Configure
Configure
BYO Active Directory via LDAPS
BYO Active Directory via LDAPS
Centralize database access management and eliminate
the need to recreate permissions by using your LDAP
server (over TLS/SSL) to manage user authentication
and authorization.
● LDAP groups are mapped to different MongoDB
roles in your MongoDB Atlas databases
● LDAP configuration applies to all dedicated
database clusters within an Atlas Project
● Available for deployments running MongoDB 3.4+
Database Auditing
Database Auditing
W
h
y
?
Data=
S**t
Happens!
Database Auditing
createDatabase
createCollection
createIndex
renameCollection
dropCollection
dropDatabase
authCheck
dropIndex
createUser
authenticate
dropUser
dropAllUsersFromDatabase
updateUser
grantRolesToUser
revokeRolesFromUser
createRole
updateRole
dropRole
dropAllRolesFromDatabase
grantPrivilegesToRole
addShard
enableSharding
shardCollection
removeShard
revokePrivilegesFromRole
applicationMessage
shutdown
W
h
a
t
?
Database Auditing
Answer detailed questions about system activity by tracking DDL, DML, and DCL commands.
● Easily select the actions you want audited as well as the MongoDB users, Atlas roles, or
LDAP groups you want to audit from the Atlas UI
● Alternatively, create an audit filter as a JSON string
● Auditing configuration applies to all dedicated clusters within an Atlas project
● Audit logs can be downloaded in the UI or retrieved using the MongoDB Atlas API
Database Auditing
Database Auditing
Database Auditing
Database Auditing
Database Auditing
Encryption At Rest
@
Encryption At Rest
You control the
coming soon!
W
h
y
?
Encryption At Rest
Encryption At Rest
Encryption At Rest
Encryption At Rest
Encryption At Rest
Rotation
Deletion
Encryption At Rest
MongoDB Atlas integrates with your key management
service of choice (starting with AWS KMS), allowing you
to centralize control of the keys used to encrypt your
MongoDB data
● BYO KMS leverages MongoDB’s encrypted
storage engine (AES256-CBC via OpenSSL) for
database-level encryption
● Create, import, and rotate keys for MongoDB Atlas
as well as define usage policies and audit usage
with the same console/CLI used to manage keys
for your other cloud services
Encryption At Rest
Encryption At Rest
BI Connector
BI Connector
No hablo MQL!
No hay problema.
Entiendo SQL!
BI Connector
BI Connector
BI Connector
BI Connector
Coming Attractions
Custom Roles
Temporary Users
Temporary Whitelist Support
x509 Authentication
Azure KeyVault
Google KMS
Advanced BI Connector Configuration
Q&A

MongoDB Atlas for Your Enterprise