# OIDC with Azure not logged in on Kibana

**URL:** <https://discuss.elastic.co/t/oidc-with-azure-not-logged-in-on-kibana/343680>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [September 23, 2023, 9:46pm UTC](https://discuss.elastic.co/t/oidc-with-azure-not-logged-in-on-kibana/343680 "2023-09-23T21:46:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![esanolad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/esanolad/32/125960_2.png) [@esanolad](https://discuss.elastic.co/u/esanolad)\
**Post date:** [September 23, 2023, 9:46pm UTC](https://discuss.elastic.co/t/oidc-with-azure-not-logged-in-on-kibana/343680/1 "2023-09-23T21:46:37Z")

</div>

Hi all

My company is configuring SSO using OIDC on AZURE, everything looks fine but whenever user tries to authenticate, it takes them back to the to the login page. I have checked the logs, there are no errors and there are no errors on the web interface as well.

I am suspecting role mapping issues, I have tried all the settings for role mapping but no result.

Below is my Config on elasticsearch.yml:

```auto
xpack.security.authc.realms.oidc.oidc1:
  order: 2
  rp.client_id: "057b9390-a441-44f9-9275-44600dd52a77"
  rp.response_type: code
  rp.redirect_uri: "https://my-domain.com:5601/app/security/oidc/callback"
  op.issuer: "https://login.microsoftonline.com/9be35454-2258-4efc-85fb-3da619c8bdb3/v2.0"
  op.authorization_endpoint: "https://login.microsoftonline.com/9be35454-2258-4efc-85fb-3da619c8bdb3/oauth2/v2.0/authorize"
  op.token_endpoint: "https://login.microsoftonline.com/9be35454-2258-4efc-85fb-3da619c8bdb3/oauth2/v2.0/token"
  op.jwkset_path: "https://login.microsoftonline.com/9be35454-2258-4efc-85fb-3da619c8bdb3/discovery/v2.0/keys"
  op.endsession_endpoint: "https://login.microsoftonline.com/9be35454-2258-4efc-85fb-3da619c8bdb3/oauth2/v2.0/logout"
  rp.post_logout_redirect_uri: "https://my-domain.com:5601/security/logged_out"
  claims.principal: sub

```

and kibana.yml:

```auto
xpack.security.authc.providers:
  oidc.oidc1:
    order: 0
    realm: "oidc1"
    description: "Log in with your account" 
  basic.basic1:
    order: 1

```

I also enable trace logging on cluster settings, but I have not seen any logs. Is there a way to check the logs for this error?

---

<div class="post-metadata">

**Author:** ![Michael\_Olorunnisola](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_olorunnisola/32/88980_2.png) [@Michael\_Olorunnisola](https://discuss.elastic.co/u/Michael_Olorunnisola)\
**Post date:** [September 25, 2023, 6:11pm UTC](https://discuss.elastic.co/t/oidc-with-azure-not-logged-in-on-kibana/343680/2 "2023-09-25T18:11:22Z")

</div>

@esanolad - Thanks for reaching out. Would it be possible for you to post this in the Elastic Stack channel with the tag #elastic-stack-security ? I'll try and point this issue in the direction of the right team, but wanted to make sure it gets the right eyes on it. Thanks!

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [September 26, 2023, 12:45pm UTC](https://discuss.elastic.co/t/oidc-with-azure-not-logged-in-on-kibana/343680/3 "2023-09-26T12:45:29Z")

</div>

Hey @esanolad, welcome to the discussion boards!

Your `rp.redirect_uri` looks incorrect. It should read `.../api/security/...`, not `.../app/security/...`:

```diff
- rp.redirect_uri: "https://my-domain.com:5601/app/security/oidc/callback"
+ rp.redirect_uri: "https://my-domain.com:5601/api/security/oidc/callback"

```

If changing this (& restarting Elasticsearch) doesn't fix your issues, then I suggest enabling debug logging for Kibana's security plugin so we can get more information about what's happening during the login flow:

```yml
# kibana.yml
logging:
  loggers:
    - name: plugins.security
      level: debug

```

---

<div class="post-metadata">

**Author:** ![esanolad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/esanolad/32/125960_2.png) [@esanolad](https://discuss.elastic.co/u/esanolad)\
**Post date:** [September 27, 2023, 6:40pm UTC](https://discuss.elastic.co/t/oidc-with-azure-not-logged-in-on-kibana/343680/4 "2023-09-27T18:40:38Z")

</div>

hi @Michael_Olorunnisola, thank you for the reply. the post has the tag already. I have implemented it using saml instead of oidc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2023, 6:41pm UTC](https://discuss.elastic.co/t/oidc-with-azure-not-logged-in-on-kibana/343680/5 "2023-10-25T18:41:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
