<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Cloud SAML Auth Admins Unable to Edit User Roles in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741151#M18370</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/265899"&gt;@jbeach&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you review this? I don't see any known issues related to your concern.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/ReleaseNotes/Issues" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/ReleaseNotes/Issues&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I kindly ask you to submit a Splunk Support ticket.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Mar 2025 17:02:19 GMT</pubDate>
    <dc:creator>kiran_panchavat</dc:creator>
    <dc:date>2025-03-07T17:02:19Z</dc:date>
    <item>
      <title>Splunk Cloud SAML Auth Admins Unable to Edit User Roles</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741149#M18369</link>
      <description>&lt;P&gt;Splunk Cloud had an update this past Sunday, 3 Mar 2025. Since then, admins are unable to change a user's role. Is this a bug?&lt;/P&gt;&lt;P&gt;We use the Chargeback App, and have it configured to use user roles to delineate charges per team.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 16:42:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741149#M18369</guid>
      <dc:creator>jbeach</dc:creator>
      <dc:date>2025-03-07T16:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud SAML Auth Admins Unable to Edit User Roles</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741151#M18370</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/265899"&gt;@jbeach&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you review this? I don't see any known issues related to your concern.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/ReleaseNotes/Issues" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/ReleaseNotes/Issues&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I kindly ask you to submit a Splunk Support ticket.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 17:02:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741151#M18370</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-07T17:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud SAML Auth Admins Unable to Edit User Roles</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741152#M18371</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/265899"&gt;@jbeach&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the title you mention SAML Auth - Are your users using SAML to login to Splunk Cloud, if so the role mappings for them should be managed by the authentication provider. Its possible that a change was made to prevent admins from trying to manually change these role mappings, as they are overwritten when a user logs in to Splunk Cloud.&lt;/P&gt;&lt;P&gt;One thing you could check is if you're able to modify the role of any non-SAML based users to rule out other issues.&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 17:03:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741152#M18371</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-07T17:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud SAML Auth Admins Unable to Edit User Roles</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741153#M18372</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I checked the non-SAML users and I can edit them.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am waiting on our Splunk Engineer to answer internally, but I think your answer is most plausible. Unfortunate, but plausible.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 17:14:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741153#M18372</guid>
      <dc:creator>jbeach</dc:creator>
      <dc:date>2025-03-07T17:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud SAML Auth Admins Unable to Edit User Roles</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741154#M18373</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264857"&gt;@kiran_panchavat&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you. I have a request in to our Splunk Engineer. I am afraid they are going to tell me what&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;said--that the roles must be mapped by the auth provider.&lt;BR /&gt;&lt;BR /&gt;I did look at your link, and do not see anything related to my concern--as you stated.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 17:16:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741154#M18373</guid>
      <dc:creator>jbeach</dc:creator>
      <dc:date>2025-03-07T17:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud SAML Auth Admins Unable to Edit User Roles</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741157#M18374</link>
      <description>&lt;P&gt;Ive had a look through a bunch of the release notes for recent versions and there is no mention of a change in behaviour for this, or it listed as a bug fix, but again, that doesnt mean it has not been changed!&lt;/P&gt;&lt;P&gt;For the customers I have setup SAML for I've always had make a point of telling them to manage the access via the IdP. Also, dont forget that users wont automatically be deleted if they're removed from the IdP unless authentication extensions is configured. Anyway..back to the issue! Please let us know how you get on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Glad to hear people using the chargeback app, I used it a couple of years ago and whilst it took a bit of setting up, it was great once in place!&lt;/P&gt;&lt;P&gt;Good luck &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 17:31:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Cloud-SAML-Auth-Admins-Unable-to-Edit-User-Roles/m-p/741157#M18374</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-07T17:31:30Z</dc:date>
    </item>
  </channel>
</rss>

