# SAML error with ELK Stack

**URL:** <https://discuss.elastic.co/t/saml-error-with-elk-stack/164673>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 17, 2019, 3:44pm UTC](https://discuss.elastic.co/t/saml-error-with-elk-stack/164673 "2019-01-17T15:44:38Z")\
**Posts on this page:** 1\
**Showing post:** 23

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [February 26, 2019, 3:17pm UTC](https://discuss.elastic.co/t/saml-error-with-elk-stack/164673/23 "2019-02-26T15:17:40Z")

</div>

> [@vapetri](#):
>
> Thanks for the answer.  
> attribute.groups from SAML is "role" as my idp is sending me in SAML token the role:  
> look here SAML token:

I see. You still need to remove `{ "field": { "role": "Role.AT" } }` from your role mapping,

```auto
PUT /_xpack/security/role_mapping/Role.AT
{
  "roles": ["Role.AT"],
  "enabled": true,
  "rules": { "all": [
    { "field": { "realm.name": "saml1" } },
    { "field": { "groups": "Role.AT" } },
  ] }
}

```

should work fine for you.

`kibana_dashboard_only_user` role is not compatible with spaces in the way you try to use it. See [this answer](https://discuss.elastic.co/t/kibana-user-roles-kibana-dashboard-only-and-limit-spaces/161905/4?) from @Brandon_Kobel explaining why and what you can do instead

---

_[View the full topic](https://discuss.elastic.co/t/saml-error-with-elk-stack/164673)._
