# Elastic Cloud Kibana with Single Sign On from Azure Active Directory

**URL:** <https://discuss.elastic.co/t/elastic-cloud-kibana-with-single-sign-on-from-azure-active-directory/228947>\
**Category:** Kibana\
**Created:** [April 21, 2020, 2:30am UTC](https://discuss.elastic.co/t/elastic-cloud-kibana-with-single-sign-on-from-azure-active-directory/228947 "2020-04-21T02:30:56Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jpigott](https://avatars.discourse-cdn.com/v4/letter/j/d07c76/32.png) [@jpigott](https://discuss.elastic.co/u/jpigott)\
**Post date:** [April 21, 2020, 2:30am UTC](https://discuss.elastic.co/t/elastic-cloud-kibana-with-single-sign-on-from-azure-active-directory/228947/1 "2020-04-21T02:30:56Z")

</div>

Is it possible to use Azure Active Directory with the Elastic Cloud Kibana?

I see this other article, but it looks like this is probably on-premises?

> [@SAML configuration - Azure Active Directory](https://discuss.elastic.co/t/saml-configuration-azure-active-directory/182314/4):
>
> I resolved this myself. I was missing the role mapping from AD roles -\> elasticsearch roles. Thanks for your help!

and

> **[Active Directory User Authentication | X-Pack for the Elastic Stack \[6.2\] |...](https://www.elastic.co/guide/en/x-pack/current/active-directory-realm.html)**

If there is a good article to set this up that would be nice to see.

Thanks!

Jeff

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [April 21, 2020, 2:54am UTC](https://discuss.elastic.co/t/elastic-cloud-kibana-with-single-sign-on-from-azure-active-directory/228947/2 "2020-04-21T02:54:45Z")

</div>

Hi @jpigott,

Are you using our SaaS offering for Elastic Cloud? If so, I found this documentation that may help:

[https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-SAML.html](https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-SAML.html)

Which references this blog post also:

> **[SAML Authentication and the Elastic Stack](https://www.elastic.co/blog/how-to-enable-saml-authentication-in-kibana-and-elasticsearch)**
>
> The Elastic Stack is a SAML 2.0 compliant Service Provider that implements the Web Browser SSO and Single Logout profiles. Kibana and Elasticsearch are the two major components of the Elastic Stack that contribute to the SAML related functionality.

Let us know if this helps,

Thanks,  
Liza

---

<div class="post-metadata">

**Author:** ![jpigott](https://avatars.discourse-cdn.com/v4/letter/j/d07c76/32.png) [@jpigott](https://discuss.elastic.co/u/jpigott)\
**Post date:** [April 21, 2020, 3:15am UTC](https://discuss.elastic.co/t/elastic-cloud-kibana-with-single-sign-on-from-azure-active-directory/228947/3 "2020-04-21T03:15:34Z")

</div>

Yes I am using your SaaS offering. It would be great if there was a walkthrough on how to do this step by step with Azure Active Directory. Thanks.

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [April 21, 2020, 3:26am UTC](https://discuss.elastic.co/t/elastic-cloud-kibana-with-single-sign-on-from-azure-active-directory/228947/4 "2020-04-21T03:26:11Z")

</div>

Thanks Jeff,

Yes I understand, let me check with one of our cloud experts @Alex_Piggott to see if knows of any other documentation or can help with steps.

Regards,  
Liza

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 21, 2020, 5:59am UTC](https://discuss.elastic.co/t/elastic-cloud-kibana-with-single-sign-on-from-azure-active-directory/228947/6 "2020-04-21T05:59:19Z")

</div>

Here's a list of the limitations around security features that you might want to check - [https://www.elastic.co/guide/en/cloud/current/ec-restrictions.html#ec-restrictions-security](https://www.elastic.co/guide/en/cloud/current/ec-restrictions.html#ec-restrictions-security).

As the [AD integration use LDAP](https://www.elastic.co/guide/en/elasticsearch/reference/current/active-directory-realm.html), AD is not supported at this stage sorry to say.

But, there is an AD product (Active Directory Federation Services) that provides SAML authentication on top of AD-DS, and "Azure AD" is Microsoft's cloud identity product which also supports SAML. So technically the AD suite of products can do SAML, but customers would reasonably expect that "Active Directory" means AD-DS unless we're really explicit about meaning something else.

The Elasticsearch feature called an "active directory" realm doesn't work in ESS. But customers who have the AD suite of products can authenticate to Kibana using SAML with ADFS.

---

<div class="post-metadata">

**Author:** ![jpigott](https://avatars.discourse-cdn.com/v4/letter/j/d07c76/32.png) [@jpigott](https://discuss.elastic.co/u/jpigott)\
**Post date:** [April 21, 2020, 1:07pm UTC](https://discuss.elastic.co/t/elastic-cloud-kibana-with-single-sign-on-from-azure-active-directory/228947/7 "2020-04-21T13:07:55Z")

</div>

Ok thanks I am really just looking for setting up single sign on to Kibana. Are there limitations to having our clusters stood up in Azure vs. AWS for this setup. Have you successfully implemented this solutions with customers that use Azure Active Directory? This article references Azure Active Directory Premium as well which I'd like to confirm is needed, and wasn't sure if this was allowed to connect to the cloud instance.

> **[SAML based Single Sign-On with Elasticsearch and Azure Active Directory](https://www.elastic.co/blog/saml-based-single-sign-on-with-elasticsearch-and-azure-active-directory)**
>
> Introducing integration of SAML Single Sign-On with Azure Active Directory and our Elastic ARM template offering, including a walkthrough of the steps involved.

Thanks!

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 22, 2020, 8:39am UTC](https://discuss.elastic.co/t/elastic-cloud-kibana-with-single-sign-on-from-azure-active-directory/228947/8 "2020-04-22T08:39:27Z")

</div>

Hi Jeff,

> Are there limitations to having our clusters stood up in Azure vs. AWS for this setup.

No.

> [@jpigott](#):
>
> Have you successfully implemented this solutions with customers that use Azure Active Directory?

I have seen numerous cloud users setting up SAML SSO with Azure AD

> [@jpigott](#):
>
> This article references Azure Active Directory Premium as well which I'd like to confirm is needed, and wasn't sure if this was allowed to connect to the cloud instance.

The article refers to premium needed in Azure and explicitly mentions

> Enabling SSO features for a non-gallery application in [Azure Active Directory](https://azure.microsoft.com/en-au/services/active-directory/) requires a premium tier of AAD. If you're running on the free or basic tier, it's possible to try the P2 premium tier features for free for a trial period, after which you need to decide whether to continue with it and be billed for usage, or to revert back to the free tier. For the purposes of this post, a trial of Azure Premium P2 will suffice.

I am unaware if this is still the case but your Azure support contact or their documentation would probably be a more authoritative source for this as this is an Azure AD and not an Elastic limitation.

> [@jpigott](#):
>
> and wasn't sure if this was allowed to connect to the cloud instance.

A small comment here is that with SAML SSO, your Azure AD instance ( being the SAML Identity Provider ) and the Elastic Cloud instance ( being the SAML Service Provider ) do not need to connect to each other _at all_ . The whole SSO flow happens through the user's browser.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2020, 8:39am UTC](https://discuss.elastic.co/t/elastic-cloud-kibana-with-single-sign-on-from-azure-active-directory/228947/9 "2020-05-20T08:39:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
