# Elasticsearch SAML integration while using HTTP-Redirect

**URL:** <https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 12, 2018, 2:08am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658 "2018-07-12T02:08:19Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 12, 2018, 3:29am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658/2 "2018-07-12T03:29:54Z")

</div>

When you say "AD", I assume you mean ADFS - is that correct?

ADFS can support HTTP-Redirect and has been successfully used with the Elastic Stack. You may need to look at configuration options for your AD install.

> 1 if we use SSO, Do AD server have to support HTTP-Redirect?

Your Identity Provider must support a HTTP-Redirect binding for sign on, yes.  
It's OK if it supports additional bindings, but we require a Redirect binding.

> 2 if the answer is yes ,why.

Because implementing support for each binding type is additional work, and we have chosen to implement HTTP-Redirect support, because it is required by the SAML comformance spec and all interoperability profiles.

> 3 can i disable SSO temporarily. how?

You can turn off SAML support in Kibana.

See: "[SingleSignOnService Binding HTTP-POST](https://discuss.elastic.co/t/singlesignonservice-binding-http-post/134474)" for previous discussion on this topic.

---

_[View the full topic](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658)._
