# Okta - ElastiCloud - We hit an authentication error. Please check your credentials and try again

**URL:** <https://discuss.elastic.co/t/okta-elasticloud-we-hit-an-authentication-error-please-check-your-credentials-and-try-again/300882>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [March 28, 2022, 6:02pm UTC](https://discuss.elastic.co/t/okta-elasticloud-we-hit-an-authentication-error-please-check-your-credentials-and-try-again/300882 "2022-03-28T18:02:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![chasep](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@chasep](https://discuss.elastic.co/u/chasep)\
**Post date:** [March 28, 2022, 6:02pm UTC](https://discuss.elastic.co/t/okta-elasticloud-we-hit-an-authentication-error-please-check-your-credentials-and-try-again/300882/1 "2022-03-28T18:02:00Z")

</div>

Hi,

Setting up OKTA\<-\>ElasticCloud SAML 2.0.  
For Reference, I have followed the steps from following.

1. [Integrating Elastic Cloud Kibana with Okta SAML SSO in 2021 - BioTeam](https://bioteam.net/blog/tech/networking/integrating-elastic-cloud-kibana-with-okta-saml-sso-in-2021/)
2. [Secure your clusters with SAML | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-SAML.html)

However, I am getting an error as following when I select 'ElasticCloud' from Okta  
"We hit an authentication error. Please check your credentials and try again. If you still can't log in, contact your system administrator."

Also, checked

```auto
GET _security/_authenticate 

```

and got following response

```auto
{
  "username" : "xxx@xya.z",
  "roles" : [
    "superuser",
    "kibana_admin",
    "kibana_system",
    "custom_reporting_user"
  ],
  "full_name" : "<full name>",
  "email" : "xxx@xya.z",
  "metadata" : { },
  "enabled" : true,
  "authentication_realm" : {
    "name" : "native",
    "type" : "native"
  },
  "lookup_realm" : {
    "name" : "native",
    "type" : "native"
  },
  "authentication_type" : "realm"
}

```

Below is the URL it is hitting as soon as it is navigated from OKTA

```auto
https://<KibanaEndpoint>.aws.found.io:9243/login?next=%2F&msg=UNAUTHENTICATED)

```

Screenshot of Error Message

 ![Screen Shot 2022-03-28 at 1.41.26 PM](https://us1.discourse-cdn.com/elastic/original/3X/5/7/57740c0b782c559eaab50ea805235015a29de811.png)

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [April 11, 2022, 10:54am UTC](https://discuss.elastic.co/t/okta-elasticloud-we-hit-an-authentication-error-please-check-your-credentials-and-try-again/300882/2 "2022-04-11T10:54:00Z")

</div>

Hi @chasep ,

It's hard to say what's going on here without logs, have you seen anything suspicious in the KIbana logs?

> [@chasep](#):
>
> ```auto
> "authentication_realm" : {
> "name" : "native",
> "type" : "native"
> },
> 
> ```

Hmm, it's not a SAML/Okta user - it's just a native elasticsearch user. What exactly you tried to check with this request?

> [@chasep](#):
>
> ```auto
> "roles" : [
> "superuser",
> "kibana_admin",
> "kibana_system",
> "custom_reporting_user"
> ],
> 
> ```

By the way, if you have a `superuser` role for the user, you don't need any other roles, it covers everything already (and `kibana_system` shouldn't be assigned to the users anyway).

Best,  
Oleg

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2022, 10:54am UTC](https://discuss.elastic.co/t/okta-elasticloud-we-hit-an-authentication-error-please-check-your-credentials-and-try-again/300882/3 "2022-05-09T10:54:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
