Our Splunk architecture is using SAML. Users are randomly added to our SAML mapped groups without authorization (too many cooks in the Azure kitchen).
Has anybody found a way to control SAML accounts @ the Splunk level? Or is this exclusively out of the control of Splunk?