# How to Azure Entra ID Groups for SAML SSO?

**URL:** <https://discuss.elastic.co/t/how-to-azure-entra-id-groups-for-saml-sso/352340>\
**Category:** Elasticsearch\
**Created:** [February 1, 2024, 9:53pm UTC](https://discuss.elastic.co/t/how-to-azure-entra-id-groups-for-saml-sso/352340 "2024-02-01T21:53:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![World\_Python](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/world_python/32/124600_2.png) [@World\_Python](https://discuss.elastic.co/u/World_Python)\
**Post date:** [February 1, 2024, 9:53pm UTC](https://discuss.elastic.co/t/how-to-azure-entra-id-groups-for-saml-sso/352340/1 "2024-02-01T21:53:39Z")

</div>

Following these docs:

> **[Set up SAML with Microsoft Entra ID | Elasticsearch Service Documentation |...](https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-saml-azure.html)**

Config:

```auto
xpack:
  security:
    authc:
      realms:
        saml:
          saml1:
            order: 3
            attributes.dn: "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"
            attributes.principal: "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"
            attributes.groups: "http://schemas.microsoft.com/ws/2008/06/identity/claims/groups"
            idp.metadata.path: "https://login.microsoftonline.com/UUID/federationmetadata/2007-06/federationmetadata.xml?appid=UUID"
            idp.entity_id: "https://sts.windows.net/UUID-e1d-9540-UUID/"
            sp.entity_id: "https://elastic-kibana-development.example.com"
            sp.acs: "https://elastic-kibana-development.example.com/api/security/saml/callback"
            sp.logout: "https://elastic-kibana-development.elastic.com/logout"

```

Have an app in Azure Entra ID, with a group Named Admins

Created a rolemapping to associate superuser to groups to the Admin group...

When I click kibana SSO.. I go through the Microsoft SSO login process but fails with You do not have permission to access the requested page.

How do I pass the groups form Azure into Elastic role mapping?

Thank you.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 1, 2024, 11:38pm UTC](https://discuss.elastic.co/t/how-to-azure-entra-id-groups-for-saml-sso/352340/2 "2024-02-01T23:38:50Z")

</div>

You haven't provided enough information for us to know where this is failing.

It could be in your Entra ID config, or in your `elasticsearch.yml` config, or in your role mapping.

Please provide a complete description of what you have configured so we can look any possible issues.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 29, 2024, 11:38pm UTC](https://discuss.elastic.co/t/how-to-azure-entra-id-groups-for-saml-sso/352340/3 "2024-02-29T23:38:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
