Security

Roles not assigned to SAML users

roshanadabala
Observer

I have added a New SAML group and assigned a role which was created before with limited privileges/capabilities and access to only 2 indexes. However, users in that group have reported being unable to access the resources(indexes). Upon verifying in the users section of Splunk Cloud settings, I noticed that the specific users within that AD group were not assigned their roles. Is there a troubleshooting step I should take? I noticed an option in the SAML settings to reload the SAML configuration, but I am worried to click on it.

Labels (3)
0 Karma

HiramMann
Loves-to-Learn

A safe first step is to verify that the group attribute in your IdP (such as AD/Okta/Azure AD) exactly matches what is configured in Splunk’s SAML group mapping. Small differences like case sensitivity or spacing can cause issues. You can also try the Reload SAML Configuration option, it simply refreshes the configuration and mappings without disrupting service, so it is generally safe to use when troubleshooting.

0 Karma

Kai
New Member

try Enable Auto Mapped Roles

0 Karma

prakaagr
Loves-to-Learn

HI roshnadabala

Wondering if you are able to resolve it..I am seeing the same issue across multiple SH clusters.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...