# Unable to authenticate user \[\<unauthenticated-saml-user\>

**URL:** <https://discuss.elastic.co/t/unable-to-authenticate-user-unauthenticated-saml-user/382124>\
**Category:** Kibana\
**Created:** [September 22, 2025, 2:11pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-unauthenticated-saml-user/382124 "2025-09-22T14:11:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![madhavsankarg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madhavsankarg/32/136239_2.png) [@madhavsankarg](https://discuss.elastic.co/u/madhavsankarg)\
**Post date:** [September 22, 2025, 2:11pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-unauthenticated-saml-user/382124/1 "2025-09-22T14:11:12Z")

</div>

Hi All,

I have Updated the Elasticstack from 8.14.1 to 8.18.1.

Currently encountering error of SAML login. In our setup we are using SSO of Azure to login to Kibana.

Error I am getting in kibana logs

> {"event":{"action":"user\_login","category":["authentication"],"outcome":"failure"},"kibana":{"session\_id":"qwertyui","authentication\_provider":"kibana-realm","authentication\_type":"saml"},"error":{"code":"ResponseError","message":"security\_exception\n\tRoot causes:\n\t\tsecurity\_exception: unable to authenticate user for action [cluster:admin/xpack/security/saml/authenticate]"},"trace":{"id":"dd0bc6c3-28c9-42b1-9b5c-d4ae13810446"},"client":{"ip":"10.160.0.89"},"service":{"node":{"roles":["background\_tasks","ui"]}},"ecs":{"version":"8.11.0"},"@timestamp":"2025-09-22T12:03:30.389+02:00","message":"Failed attempt to login using saml provider [name=kibana-realm]","log":{"level":"INFO","logger":"plugins.security.audit.ecs"},"process":{"pid":1181,"uptime":18037.822102144},"transaction":{"id":"123456"}}  
> {"event":{"action":"saved\_object\_open\_point\_in\_time","category":["database"],"type":["creation"],"outcome":"unknown"},"kibana":{"space\_id":"devops"},"trace":{"id":"qwertyuij"},"client":{},"service":{"node":{"roles":["background\_tasks","ui"]}},"ecs":{"version":"8.11.0"},"@timestamp":"2025-09-22T12:03:35.448+02:00","message":"User is opening point-in-time saved objects","log":{"level":"INFO","logger":"plugins.security.audit.ecs"},"process":{"pid":1181,"uptime":18042.881158752},"transaction":{"id":"801e1475a1c5d976"}}  
> {"event":{"action":"saved\_object\_open\_point\_in\_time","category":["database"],"type":["creation"],"outcome":"unknown"},"kibana":{"space\_id":"devops"},"trace":{"id":"1234567"},"client":{},"service":{"node":{"roles":["background\_tasks","ui"]}},"ecs":{"version":"8.11.0"},"@timestamp":"2025-09-22T12:03:35.450+02:00","message":"User is opening point-in-time saved objects","log":{"level":"INFO","logger":"plugins.security.audit.ecs"},"process":{"pid":1181,"uptime":18042.883200968},"transaction":{"id":"693bdf39eaff7e26"}}

---

<div class="post-metadata">

**Author:** ![madhavsankarg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/madhavsankarg/32/136239_2.png) [@madhavsankarg](https://discuss.elastic.co/u/madhavsankarg)\
**Post date:** [September 22, 2025, 2:22pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-unauthenticated-saml-user/382124/2 "2025-09-22T14:22:23Z")

</div>

Hi All,

Is this issue related to  
[Elasticsearch version 8.18.0 | Elasticsearch Guide [8.18] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.18/release-notes-8.18.0.html#:%5C~:text=Active%20Directory%20authentication,%23126992) )

and the fix is not in 8.18.1 version ?
