# Azure AD SAML auth - 403 - Forbidden

**URL:** <https://discuss.elastic.co/t/azure-ad-saml-auth-403-forbidden/185900>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 14, 2019, 7:12pm UTC](https://discuss.elastic.co/t/azure-ad-saml-auth-403-forbidden/185900 "2019-06-14T19:12:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![OJA](https://avatars.discourse-cdn.com/v4/letter/o/e19adc/32.png) [@OJA](https://discuss.elastic.co/u/OJA)\
**Post date:** [June 14, 2019, 7:12pm UTC](https://discuss.elastic.co/t/azure-ad-saml-auth-403-forbidden/185900/1 "2019-06-14T19:12:41Z")

</div>

Hi, (oh wow, sorry, I obviously don't understand how to use the \</\> tag..)

Spent a few hours configuring and reading the documentation, and I'm getting very close to completing the setup (I feel).  
But I need some help with the final sprint.

This is on a new single Elastic/Kibana cloud deployment.

**The error I'm now getting after authenticating to Kibana is:**  
|statusCode|403|  
|---|---|  
|error|"Forbidden"|  
|message|"Forbidden"|

**Elastic config:**  
xpack:  
security:  
authc:  
realms:  
saml:  
cloud-saml:  
order: 2  
attributes.principal: "[http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name)"  
attributes.groups: "[http://schemas.microsoft.com/ws/2008/06/identity/claims/role](http://schemas.microsoft.com/ws/2008/06/identity/claims/role)"  
idp.metadata.path: "[https://login.microsoftonline.com/REMOVED/federationmetadata/2007-06/federationmetadata.xml?appid=REMOVED](https://login.microsoftonline.com/REMOVED/federationmetadata/2007-06/federationmetadata.xml?appid=REMOVED)"  
idp.entity\_id: "[https://sts.windows.net/REMOVED/](https://sts.windows.net/REMOVED/)"  
sp.entity\_id: "[https://REMOVED.eu-west-1.aws.found.io:9243/](https://REMOVED.eu-west-1.aws.found.io:9243/)"  
sp.acs: "[https://REMOVED.eu-west-1.aws.found.io:9243/api/security/v1/saml](https://REMOVED.eu-west-1.aws.found.io:9243/api/security/v1/saml)"  
sp.logout: "[https://REMOVED.eu-west-1.aws.found.io:9243/logout](https://REMOVED.eu-west-1.aws.found.io:9243/logout)"

**Kibana config:**  
xpack.security.authProviders: [saml, basic]  
server.xsrf.whitelist: [/api/security/v1/saml]  
xpack.security.public:  
protocol: https  
hostname: [REMOVED.eu-west-1.aws.found.io](http://REMOVED.eu-west-1.aws.found.io)  
port: 9243

**Azure Enterprise app config:**  
Identifier (Entity ID) - [https://REMOVED.eu-west-1.aws.found.io:9243/](https://REMOVED.eu-west-1.aws.found.io:9243/)

Reply URL (Assertion Consumer Service URL) - [https://REMOVED.eu-west-1.aws.found.io:9243/api/security/v1/saml](https://REMOVED.eu-west-1.aws.found.io:9243/api/security/v1/saml)

**Added claim:**  
[http://schemas.microsoft.com/ws/2008/06/identity/claims/role](http://schemas.microsoft.com/ws/2008/06/identity/claims/role) - user.assignedroles

**Azure Application Registration Manifest config:**  
{  
"allowedMemberTypes": [  
"User"  
],  
"displayName": "Superuser",  
"id": "REMOVED",  
"isEnabled": true,  
"description": "Superuser with administrator access",  
"value": "superuser"  
},  
{  
"allowedMemberTypes": [  
"User"  
],  
"description": "Kibana User",  
"displayName": "Kibana User",  
"id": "REMOVED",  
"isEnabled": true,  
"value": "kibana\_user"  
}

The application validation in Azure succeeds, and I can see the role is included in the SAML response.  
But Elastic does not seem to agree, or is misconfigured somewhere.

Any ideas, or obvious issues here?

---

<div class="post-metadata">

**Author:** ![OJA](https://avatars.discourse-cdn.com/v4/letter/o/e19adc/32.png) [@OJA](https://discuss.elastic.co/u/OJA)\
**Post date:** [June 15, 2019, 9:22pm UTC](https://discuss.elastic.co/t/azure-ad-saml-auth-403-forbidden/185900/2 "2019-06-15T21:22:55Z")

</div>

Solved it.  
Had ignored the part about role mapping via API.

For reference if this happens to a future person: [https://www.elastic.co/guide/en/elastic-stack-overview/current/saml-role-mapping.html](https://www.elastic.co/guide/en/elastic-stack-overview/current/saml-role-mapping.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2019, 9:22pm UTC](https://discuss.elastic.co/t/azure-ad-saml-auth-403-forbidden/185900/3 "2019-07-13T21:22:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
