# How to allow Users access Kibana on Elastic Cloud on Azure?

**URL:** <https://discuss.elastic.co/t/how-to-allow-users-access-kibana-on-elastic-cloud-on-azure/278381>\
**Category:** Kibana\
**Created:** [July 12, 2021, 7:17am UTC](https://discuss.elastic.co/t/how-to-allow-users-access-kibana-on-elastic-cloud-on-azure/278381 "2021-07-12T07:17:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![idelix](https://avatars.discourse-cdn.com/v4/letter/i/ecd19e/32.png) [@idelix](https://discuss.elastic.co/u/idelix)\
**Post date:** [July 12, 2021, 7:17am UTC](https://discuss.elastic.co/t/how-to-allow-users-access-kibana-on-elastic-cloud-on-azure/278381/1 "2021-07-12T07:17:18Z")

</div>

I deployed: Elastic Cloud (Elasticsearch managed service) [Elastic Cloud (Elasticsearch managed service)](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/elastic.ec-azure?tab=overview)

Now I need to allow users from my Azure tenant to access Kibana using their Azure AD credentials so to do something like described here: [SAML based Single Sign-On with Elasticsearch and Azure Active Directory | Elastic Blog](https://www.elastic.co/blog/saml-based-single-sign-on-with-elasticsearch-and-azure-active-directory)

But seems like Enterprise App that was created automatically do not allow me to create any mafiest or to be managed at all....

I'm getting this:  
"The single sign-on configuration is not available for this application in the Enterprise applications experience. Elastic Cloud (Managed Service) is a multi-tenant application and the application is owned by another tenant."

Please advise how I can allow users form my tenant to access Kibana without creating separate elastci account for each person

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [July 13, 2021, 1:12pm UTC](https://discuss.elastic.co/t/how-to-allow-users-access-kibana-on-elastic-cloud-on-azure/278381/2 "2021-07-13T13:12:27Z")

</div>

Hey @idelix, welcome to the discussion boards!

I'm not terribly familiar with the Azure marketplace, but we do have instructions for connecting Elastic Cloud to Azure AD via OpenID Connect: [Set up OpenID Connect with Azure, Google, or Okta | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-oidc-op.html#ec-securing-oidc-azure).

It sounds like the error message you're getting is from Azure, so these instructions may or may not be helpful. If not, I think your best bet would be to reach out to your support contact via [support.elastic.co](http://support.elastic.co) for further assistance.

---

<div class="post-metadata">

**Author:** ![idelix](https://avatars.discourse-cdn.com/v4/letter/i/ecd19e/32.png) [@idelix](https://discuss.elastic.co/u/idelix)\
**Post date:** [July 19, 2021, 11:41am UTC](https://discuss.elastic.co/t/how-to-allow-users-access-kibana-on-elastic-cloud-on-azure/278381/3 "2021-07-19T11:41:07Z")

</div>

Thank you I got this to work, had to make some changes to the original:

Elasticsearch setting had to remove this bit:  
claim\_patterns.principal: "^([^@]+)@\<domain\_name\>\.tld$"

And in Role mapping I removed firstname.surname filter

So now all users from my tenant can login and become superuser, I wonder if anyone knows how to only allow one specific Azure group ?  
Ideally I would add users to this group in Azure and they would be mapped to roles in kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 16, 2021, 11:41am UTC](https://discuss.elastic.co/t/how-to-allow-users-access-kibana-on-elastic-cloud-on-azure/278381/4 "2021-08-16T11:41:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
