<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How Do I Remove Old SAML Users? in Security</title>
    <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/642189#M16954</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Worked for me! This is great solution , specially for cloud customers.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 May 2023 20:42:15 GMT</pubDate>
    <dc:creator>dbhojani</dc:creator>
    <dc:date>2023-05-03T20:42:15Z</dc:date>
    <item>
      <title>How Do I Remove Old SAML Users?</title>
      <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356964#M8943</link>
      <description>&lt;P&gt;I originally configured my SAML authentication with a NameID that was a GUID. We noticed that they were randomly generated rather than assigned to the same user every time. We've since gone back to our IdP and changed our NameID to email address so that it stays the same each time.&lt;/P&gt;

&lt;P&gt;How do I get rid of the extra users under Settings &amp;gt; Access Controls &amp;gt; Users?&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 14:33:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356964#M8943</guid>
      <dc:creator>brreeves_splunk</dc:creator>
      <dc:date>2017-05-01T14:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: How Do I Remove Old SAML Users?</title>
      <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356965#M8944</link>
      <description>&lt;P&gt;To get rid of the users in SAML please follow the directions below.&lt;/P&gt;

&lt;P&gt;First&lt;BR /&gt;
remove the users from ~SPLUNK_HOME/etc/users&lt;/P&gt;

&lt;P&gt;Second&lt;BR /&gt;
Find the correct authentication.conf (most of the time it is located under ~SPLUNK_HOME/etc/system/local)&lt;/P&gt;

&lt;P&gt;Third,&lt;BR /&gt;
Locate the [userToRoleMap_SAML] stanza and delete the users you want to delete in SAML.&lt;/P&gt;

&lt;P&gt;Fourth,&lt;BR /&gt;
Preform a debug/refresh then reload the SAML configurations in Settings &amp;gt; Access Controls &amp;gt; Authentication Method &amp;gt; Reload SAML Settings at the bottom of your screen.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 15:31:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356965#M8944</guid>
      <dc:creator>djung</dc:creator>
      <dc:date>2017-05-01T15:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: How Do I Remove Old SAML Users?</title>
      <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356966#M8945</link>
      <description>&lt;P&gt;Does this process also apply to Splunk Cloud? That is, must I file a support ticket to get SAML users removed?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 00:19:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356966#M8945</guid>
      <dc:creator>sarah115</dc:creator>
      <dc:date>2018-07-27T00:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: How Do I Remove Old SAML Users?</title>
      <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356967#M8946</link>
      <description>&lt;P&gt;Yes @sarah115. You'd have to submit a ticket to Splunk Cloud Support to have this done.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Reassign Knowledge Objects
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.3/Knowledge/Resolveorphanedsearches#Use_the_Reassign_Knowledge_Objects_page_in_Settings"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.3/Knowledge/Resolveorphanedsearches#Use_the_Reassign_Knowledge_Objects_page_in_Settings&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Compile a list of users you want to have removed, and submit them in a support ticket with a link to think answers post for clarity on what you want done. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;Enjoy your weekend.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 27 Jul 2018 01:25:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356967#M8946</guid>
      <dc:creator>brreeves_splunk</dc:creator>
      <dc:date>2018-07-27T01:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: How Do I Remove Old SAML Users?</title>
      <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356968#M8947</link>
      <description>&lt;P&gt;Thank you very much!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 01:55:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356968#M8947</guid>
      <dc:creator>sarah115</dc:creator>
      <dc:date>2018-07-27T01:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: How Do I Remove Old SAML Users?</title>
      <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356969#M8948</link>
      <description>&lt;P&gt;You can do what you need via rest with no need to reload the config.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;curl -k -u admin:{password} --request DELETE &lt;A href="https://{hostname}:8089/services/admin/SAML-user-role-map/{user_id}" target="test_blank"&gt;https://{hostname}:8089/services/admin/SAML-user-role-map/{user_id}&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You will need to remove the user directory on disk manually.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 12:45:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356969#M8948</guid>
      <dc:creator>BenBurrows</dc:creator>
      <dc:date>2019-01-18T12:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: How Do I Remove Old SAML Users?</title>
      <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356970#M8949</link>
      <description>&lt;P&gt;This was a lot helpful, now i understood how this mechanism works.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 13:57:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356970#M8949</guid>
      <dc:creator>ashutosh2020</dc:creator>
      <dc:date>2019-03-18T13:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: How Do I Remove Old SAML Users?</title>
      <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356971#M8950</link>
      <description>&lt;P&gt;Hi BenBurrows,&lt;/P&gt;

&lt;P&gt;curl command works fine to delete any user from stand alone SH but does not work in SH Cluster environment. It gives error when I tried at one of the  SH cluster&lt;/P&gt;

&lt;P&gt;curl: (7) Failed to connect to URI port 8089: connection time out&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 04:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356971#M8950</guid>
      <dc:creator>ssharma09</dc:creator>
      <dc:date>2019-07-30T04:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: How Do I Remove Old SAML Users?</title>
      <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356972#M8951</link>
      <description>&lt;P&gt;Hi ssharma09,&lt;BR /&gt;
I was fairly confident that would work fine but I checked it just now to be sure and it does work fine in a SH Cluster. I double checked and it happens that I ran it against the Cluster Captain but I don't think that is a requirement.&lt;/P&gt;

&lt;P&gt;The error you posted leads me to believe there is some other issue for you. The error looks like a connection/network error rather than a splunk issue. Are you running the management service on that port on your SHC and are any firewalls blocking the connection? Does a connection get established if you try using telnet or netcat ? &lt;/P&gt;

&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 12:11:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356972#M8951</guid>
      <dc:creator>BenBurrows</dc:creator>
      <dc:date>2019-07-31T12:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: How Do I Remove Old SAML Users?</title>
      <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356973#M8952</link>
      <description>&lt;P&gt;Worked great for me!  This is also Splunk Cloud friendly, as we do not have access to the configuration directly.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 18:13:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/356973#M8952</guid>
      <dc:creator>markbarber21</dc:creator>
      <dc:date>2019-11-13T18:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: How Do I Remove Old SAML Users?</title>
      <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/642189#M16954</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Worked for me! This is great solution , specially for cloud customers.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 20:42:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/642189#M16954</guid>
      <dc:creator>dbhojani</dc:creator>
      <dc:date>2023-05-03T20:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: How Do I Remove Old SAML Users?</title>
      <link>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/702932#M18175</link>
      <description>&lt;P&gt;Issue still persists in Splunk enterprise. I don't know why Splunk din't fix the issue yet. However, the answer is still valid.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 16:37:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/How-Do-I-Remove-Old-SAML-Users/m-p/702932#M18175</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2024-10-28T16:37:53Z</dc:date>
    </item>
  </channel>
</rss>

