# Azure OpenID Login doesn't work

**URL:** <https://discuss.elastic.co/t/azure-openid-login-doesnt-work/255593>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 16, 2020, 8:48pm UTC](https://discuss.elastic.co/t/azure-openid-login-doesnt-work/255593 "2020-11-16T20:48:48Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![thetell75](https://avatars.discourse-cdn.com/v4/letter/t/d9b06d/32.png) [@thetell75](https://discuss.elastic.co/u/thetell75)\
**Post date:** [November 16, 2020, 8:48pm UTC](https://discuss.elastic.co/t/azure-openid-login-doesnt-work/255593/1 "2020-11-16T20:48:48Z")

</div>

Hi everyone.....

Unfortunately my azure openid configuration seems not to work.  
I've verified the openid Authentication with [OpenID Connect Playground](https://openidconnect.net/) and everything seems to be ok.

Also if I set only Realm check in Roles-Mapping the login seems to work. But if I want to specify a specific Roles Mapping it doesn't work anymore...

The claims.groups is working --\> see on [OpenID Connect Playground](https://openidconnect.net/). The Group ID's are provided by Azure.

I configured a ROle Mapping like:

put /\_security/role\_mapping/  
{  
"roles": ["Kibana-Admin"],  
"enabled": true,  
"rules": { "all": [  
{ "field": { "realm.name": "oidc1" } },  
{ "field": { "groups": "99999999-9999-9999-9999-ece1896af683" } }  
] }  
}

If I check the Logs on Kibana I get these errors:  
Nov 16 21:12:17 vm5293 kibana[904]: {"type":"log","@timestamp":"2020-11-16T20:12:17Z","tags":["debug","plugins","spaces"],"pid":904,"message":"SpacesClient.getAll(), using RBAC. Found 1 spaces"}  
Nov 16 21:12:17 vm5293 kibana[904]: {"type":"log","@timestamp":"2020-11-16T20:12:17Z","tags":["debug","plugins","spaces"],"pid":904,"message":"SpacesClient.getAll(), authorized for 0 spaces, derived from ES privilege check: {"kibana":[{"resource":"default","privilege":"login:","authorized":false}],"elasticsearch":{"cluster":,"index":{}}}"}  
Nov 16 21:12:17 vm5293 kibana[904]: {"type":"log","@timestamp":"2020-11-16T20:12:17Z","tags":["debug","plugins","spaces"],"pid":904,"message":"SpacesClient.getAll(), using RBAC. returning 403/Forbidden. Not authorized for any spaces for any purpose."}  
Nov 16 21:12:17 vm5293 kibana[904]: {"type":"log","@timestamp":"2020-11-16T20:12:17Z","tags":["debug","plugins","licensing"],"pid":904,"message":"Requesting Elasticsearch licensing API"}

Anyone do have any tipps on that?

Thanks Yours Stefan

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 16, 2020, 9:33pm UTC](https://discuss.elastic.co/t/azure-openid-login-doesnt-work/255593/2 "2020-11-16T21:33:41Z")

</div>

> [@thetell75](#):
>
> Also if I set only Realm check in Roles-Mapping the login seems to work. But if I want to specify a specific Roles Mapping it doesn't work anymore...

It looks like your [claims mapping](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/oidc-guide-authentication.html#oidc-claim-to-property) is wrong. Have you read our docs regarding this ?

> [@thetell75](#):
>
> The claims.groups is working --\> see on [OpenID Connect Playground](https://openidconnect.net/). The Group ID's are provided by Azure.

You can see that but we can't. In general, it;s always helpful to share your elasticsearch realm configuration at least. Also an example of how Azure AD sends the groups in the ID token as a claim might be useful.

---

<div class="post-metadata">

**Author:** ![thetell75](https://avatars.discourse-cdn.com/v4/letter/t/d9b06d/32.png) [@thetell75](https://discuss.elastic.co/u/thetell75)\
**Post date:** [November 16, 2020, 10:04pm UTC](https://discuss.elastic.co/t/azure-openid-login-doesnt-work/255593/3 "2020-11-16T22:04:04Z")

</div>

Hopefully this helps in resolving the issue.. I know maybe it is not ideal to use groupid, but the Group names contain Spaces, which also not really optimal...

Claim Information:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/d/8de39b47a0990f2d9b57122cfc0a1283cb84c23e.png)

Realm Configuration:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/8/b838095aa0d8cc0662ffe865bc03f5501ace4f79.png)

Kibana.yml:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/0/8007b6296dbbb84b3fce4d1dee75864e7e0bbeb5.png)

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 16, 2020, 10:27pm UTC](https://discuss.elastic.co/t/azure-openid-login-doesnt-work/255593/4 "2020-11-16T22:27:00Z")

</div>

Please don't post images of text as they are hard to read, may not display correctly for everyone, and are not searchable.

Instead, paste the text and format it with `</>` icon or pairs of triple backticks (```), and check the preview window to make sure it's properly formatted before posting it. This makes it more likely that your question will receive a useful answer.

It would be great if you could update your post to solve this.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 16, 2020, 10:28pm UTC](https://discuss.elastic.co/t/azure-openid-login-doesnt-work/255593/5 "2020-11-16T22:28:58Z")

</div>

As you can see in your ID Token, the name of the claim that carries the group information is `groups`, so according to [our docs that I referenced above](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/oidc-guide-authentication.html#oidc-claim-to-property), your configuration should be

```auto
claims.groups: groups

```

---

<div class="post-metadata">

**Author:** ![thetell75](https://avatars.discourse-cdn.com/v4/letter/t/d9b06d/32.png) [@thetell75](https://discuss.elastic.co/u/thetell75)\
**Post date:** [November 16, 2020, 10:47pm UTC](https://discuss.elastic.co/t/azure-openid-login-doesnt-work/255593/6 "2020-11-16T22:47:55Z")

</div>

Hi Ioannis,

this was the problem. I fixed it and it is working now. The problem on this claims.groups: groups is, that you'll find many different versions on the web. Depending also on the app you like to use with openid on azure...

So thank you very much... it is working now, I've tested it..

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 17, 2020, 7:14am UTC](https://discuss.elastic.co/t/azure-openid-login-doesnt-work/255593/7 "2020-11-17T07:14:29Z")

</div>

> [@thetell75](#):
>
> The problem on this claims.groups: groups is, that you'll find many different versions on the web

The value of this setting depends on the OP that is used and how it is configured to release the group information ( in which claim ) so there is not a single truth / right configuration for us to point out. We try to explain what needs to be configured and how in our docs so that users can set the value as needed.

Glad this worked, cheers !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2020, 7:14am UTC](https://discuss.elastic.co/t/azure-openid-login-doesnt-work/255593/8 "2020-12-15T07:14:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
