Hi @Kai The roles for a SAML user are sent by the identity provider when they login, not defined in Splunk. You cannot modify the roles of a SAML user in Splunk. If you need to change the roles of a SAML user this must be done in the identity provider but please note that it will not automatically update in Splunk until they next login. 🌟 Did this answer help you? If so, please consider: Adding karma to show it was useful Marking it as the solution if it resolved your issue Commenting if you need any clarification Your feedback encourages the volunteers in this community to continue contributing.
... View more