# Basic Users when SAML Enabled

**URL:** <https://discuss.elastic.co/t/basic-users-when-saml-enabled/182431>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 23, 2019, 12:20pm UTC](https://discuss.elastic.co/t/basic-users-when-saml-enabled/182431 "2019-05-23T12:20:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![shaunm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunm/32/66230_2.png) [@shaunm](https://discuss.elastic.co/u/shaunm)\
**Post date:** [May 23, 2019, 12:20pm UTC](https://discuss.elastic.co/t/basic-users-when-saml-enabled/182431/1 "2019-05-23T12:20:37Z")

</div>

Hi I am having issues getting a non reserved basic user to work with SAML SSO enabled. I have created a logstash\_internal user for logstash to use in output.

I am not able to authenticate with this user, or any other i create with superuser role, (for testing of course)  
However if i set the user to be elastic , logstash works with no issues.

Further testing I then realise i can not log on either to Kibana using a created basic user, but i can if i use the reserved elastic user

SSO is working as expected i can redirect to Azure and back to kibana once authenticated.

Is this expected behaviour?  
Identity provider is Azure AAD SSO

---

<div class="post-metadata">

**Author:** ![shaunm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunm/32/66230_2.png) [@shaunm](https://discuss.elastic.co/u/shaunm)\
**Post date:** [May 23, 2019, 12:23pm UTC](https://discuss.elastic.co/t/basic-users-when-saml-enabled/182431/2 "2019-05-23T12:23:06Z")

</div>

i am using elastic docker containers ([https://www.docker.elastic.co/#](https://www.docker.elastic.co/#)) . v6.7.1

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 23, 2019, 9:01pm UTC](https://discuss.elastic.co/t/basic-users-when-saml-enabled/182431/3 "2019-05-23T21:01:21Z")

</div>

Can you please show us the configuration ? My guess is that you enabled the SAML realm in elasticsearch without explicitly also enabling the native realm, which disables the native realm and means that users can login only via SAML.

We explain this [in our docs](https://www.elastic.co/guide/en/elasticsearch/reference/6.7/configuring-native-realm.html):

> The native realm is available by default when no other realms are configured. If other realm settings have been configured in `elasticsearch.yml` , you must add the native realm to the realm chain.

The `elastic` user is a [`built-in`](https://www.elastic.co/guide/en/elastic-stack-overview/6.7/built-in-users.html) user and as such not affected by the native realm being disabled.

In summary, you need to explicitly enable the native realm in elasticsearch's configuration, details are in the link to the documentation I shared above.

Hope this helps

---

<div class="post-metadata">

**Author:** ![shaunm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunm/32/66230_2.png) [@shaunm](https://discuss.elastic.co/u/shaunm)\
**Post date:** [May 23, 2019, 9:22pm UTC](https://discuss.elastic.co/t/basic-users-when-saml-enabled/182431/4 "2019-05-23T21:22:08Z")

</div>

Hi Ioannis

Yes you guessed correct, i only have the saml realm in y config

```auto
xpack.security.authc.realms.saml_aad:
  type: saml
  order: 2
  idp.metadata.path: /usr/share/elasticsearch/config/saml/elasticsearch.xml
  idp.entity_id: "https://sts.windows.net/xxxxxxxxxx/"
  sp.entity_id: "https://myesdomain.com:5601/"
  sp.acs: "https://myesdomain.com:5601/api/security/v1/saml"
  sp.logout: "https://myesdomain.com5601/logout"
  attributes.principal: "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name"
  attributes.name: "http://schemas.microsoft.com/identity/claims/displayname"
  attributes.mail: "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"
  attributes.groups: "http://schemas.microsoft.com/ws/2008/06/identity/claims/role"

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 24, 2019, 7:36am UTC](https://discuss.elastic.co/t/basic-users-when-saml-enabled/182431/5 "2019-05-24T07:36:54Z")

</div>

So, adding the snippet

```auto
xpack.security.authc.realms.native1:
  type: native
  order: 0

```

right above what you have, will solve your issue

---

<div class="post-metadata">

**Author:** ![shaunm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunm/32/66230_2.png) [@shaunm](https://discuss.elastic.co/u/shaunm)\
**Post date:** [May 28, 2019, 4:48pm UTC](https://discuss.elastic.co/t/basic-users-when-saml-enabled/182431/6 "2019-05-28T16:48:45Z")

</div>

Hi Ioannis

that did the trick

thanks for help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2019, 4:48pm UTC](https://discuss.elastic.co/t/basic-users-when-saml-enabled/182431/7 "2019-06-25T16:48:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
