Other Usage

No valid Splunk role found in local mapping - Microsoft Azure Entra SSO

JRacca
Explorer

Hi,

We are integrating the Splunk to our Microsoft Azure SSO, and followed instructions from https://learn.microsoft.com/en-us/entra/identity/saas-apps/splunkenterpriseandsplunkcloud-tutorial#c...

But after all the configuration, we are hitting the "No valid Splunk role found in local mapping"

 

Also checked Configure SSO with Microsoft Azure AD or AD FS as your Identity Provider - Splunk Documentation to remove the alias but was not able to make it work.

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The docs say to use the group ID or UUID.  I have little experience with Azure so I can't help much there.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Did you continue to the next step "Map SAML groups to Splunk Enterprise roles "?

---
If this reply helps you, Karma would be appreciated.

JRacca
Explorer

Yes I did and put in the Object ID of the Application created on Azure as the Group Name.
I'm trying to figure out how is it not working.

Did I put the correct Object ID?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The docs say to use the group ID or UUID.  I have little experience with Azure so I can't help much there.

---
If this reply helps you, Karma would be appreciated.

JRacca
Explorer

Hi!

Thank you! UUID did not work but Group ID did 🙂
This was my mis-out thank you

Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...