A safe first step is to verify that the group attribute in your IdP (such as AD/Okta/Azure AD) exactly matches what is configured in Splunk’s SAML group mapping. Small differences like case sensitivity or spacing can cause issues. You can also try the Reload SAML Configuration option, it simply refreshes the configuration and mappings without disrupting service, so it is generally safe to use when troubleshooting.
... View more