# Okta SSO not working

**URL:** <https://discuss.elastic.co/t/okta-sso-not-working/315053>\
**Category:** Kibana\
**Created:** [September 23, 2022, 7:23pm UTC](https://discuss.elastic.co/t/okta-sso-not-working/315053 "2022-09-23T19:23:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sean.doody](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean.doody/32/97487_2.png) [@sean.doody](https://discuss.elastic.co/u/sean.doody)\
**Post date:** [September 23, 2022, 7:23pm UTC](https://discuss.elastic.co/t/okta-sso-not-working/315053/1 "2022-09-23T19:23:54Z")

</div>

I am having trouble getting SAML integrated with Elastic. I used a 14-day Trail and got it to work there, but now that I tried to integrate it into our production environment I am getting errors.

Below is the yaml for our prod environment that isn't working. This is roughly the same that was used in our dev environment except some of the values were different due to us using Okta preview as opposed to Okta for testing.

```auto
xpack.security.authc.realms.saml:
  saml1:
    order: 2
    idp.metadata.path: 'https://company.okta.com/app/exklsxxxxxxx/sso/saml/metadata'
    idp.entity_id: 'http://www.okta.com/exklsxxxxxxxxxx'
    sp.entity_id: 'https://company.kb.us-east-1.aws.found.io:9243' # Make sure there is no trailing "/"
    sp.acs: 'https://company.kb.us-east-1.aws.found.io:9243/api/security/saml/callback'
    sp.logout: 'https://company.kb.us-east-1.aws.found.io:9243/logout'
    attributes:
      # Or replace with another SAML provider attribute you prefer to map to the username
      principal: nameid

```

This is the documentation I followed.

> **[Set up Enterprise Search with SAML 2.0 single sign-on (SSO) | Elastic...](https://www.elastic.co/guide/en/enterprise-search/current/saml-idp.html#saml-idp-idp-okta-example)**

I would also like to note that we are using a cloud-hosted environment

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 23, 2022, 9:51pm UTC](https://discuss.elastic.co/t/okta-sso-not-working/315053/2 "2022-09-23T21:51:12Z")

</div>

You should open a support ticket since you are on Elastic Cloud... After all you're paying for support. This is just the community site 🙂

---

<div class="post-metadata">

**Author:** ![sean.doody](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sean.doody/32/97487_2.png) [@sean.doody](https://discuss.elastic.co/u/sean.doody)\
**Post date:** [September 23, 2022, 10:22pm UTC](https://discuss.elastic.co/t/okta-sso-not-working/315053/3 "2022-09-23T22:22:16Z")

</div>

Hi! So they actually referred me to here since we don’t pay for consulting support only fix/break support.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 23, 2022, 10:32pm UTC](https://discuss.elastic.co/t/okta-sso-not-working/315053/4 "2022-09-23T22:32:00Z")

</div>

Ahhh I/C yes that has changed recently apologies!

Well you in the wrong docs ... you are in Enterprise Search you should be in Elasticsearch Service (Elastic Cloud) Take a look.

Normal SAML

> **[Secure your clusters with SAML | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-SAML.html)**

Here is the OpenID OKTA example I think

> **[Set up OpenID Connect with Azure, Google, or Okta | Elasticsearch Service...](https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-oidc-op.html#ec-securing-oidc-okta)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 21, 2022, 10:32pm UTC](https://discuss.elastic.co/t/okta-sso-not-working/315053/5 "2022-10-21T22:32:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
