Security

AzureAD SSO - Reply URL does not match

mattiashenrikss
Engager

I am trying to set up SSO with Splunk and AzureAD. I have used these guides: https://docs.splunk.com/Documentation/Splunk/7.1.3/Security/ConfigureSSOAzureADandADFS (Splunk) and https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/splunkenterpriseandsplunkcloud-tut... (AzureAD).

When trying to access Splunk and logging in via AzureAD, I get the following message from AzureAD: "... The reply url specified in the request does not match the reply urls configured for the application: ...". The reply url configured in AzureAD is "https://[mySplunkServer]/saml/acs".

What would be the next step to debug this? Is there a way to verify that the reply URL in Splunk is actually "https://[mySplunkServer]/saml/acs"?

Tags (2)
0 Karma

benwilinski
New Member

Have you tried changed the sso/slo binding to 'http post' on the saml config page?

Screen-Shot-2020-02-25-at-1-45-25-PM

0 Karma

mattiashenrikss
Engager

My issue was that I used the wrong name for my splunk server in the Reply URL configured in Azure AD. I found out by looking at the SAML requests/responses between Splunk and Azure AD which are logged by Splunk if DEBUG logging is activated for certain loggers.

0 Karma

LeandroKopke
Explorer

Where did you get to see this information? I'm having the same problem as you in an integration I'm doing.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...