Other Usage

No valid Splunk role found in local mapping - Microsoft Azure Entra SSO

JRacca
Explorer

Hi,

We are integrating the Splunk to our Microsoft Azure SSO, and followed instructions from https://learn.microsoft.com/en-us/entra/identity/saas-apps/splunkenterpriseandsplunkcloud-tutorial#c...

But after all the configuration, we are hitting the "No valid Splunk role found in local mapping"

 

Also checked Configure SSO with Microsoft Azure AD or AD FS as your Identity Provider - Splunk Documentation to remove the alias but was not able to make it work.

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The docs say to use the group ID or UUID.  I have little experience with Azure so I can't help much there.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Did you continue to the next step "Map SAML groups to Splunk Enterprise roles "?

---
If this reply helps you, Karma would be appreciated.

JRacca
Explorer

Yes I did and put in the Object ID of the Application created on Azure as the Group Name.
I'm trying to figure out how is it not working.

Did I put the correct Object ID?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The docs say to use the group ID or UUID.  I have little experience with Azure so I can't help much there.

---
If this reply helps you, Karma would be appreciated.

JRacca
Explorer

Hi!

Thank you! UUID did not work but Group ID did 🙂
This was my mis-out thank you

Get Updates on the Splunk Community!

Customer Experience | Splunk 2024: New Onboarding Resources

In 2023, we were routinely reminded that the digital world is ever-evolving and susceptible to new ...

Celebrate CX Day with Splunk: Take our interactive quiz, join our LinkedIn Live ...

Today and every day, Splunk celebrates the importance of customer experience throughout our product, ...

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...