# We are trying to configure Kibana with Entra ID(Azure Active directory) and it is not working properly

**URL:** <https://discuss.elastic.co/t/we-are-trying-to-configure-kibana-with-entra-id-azure-active-directory-and-it-is-not-working-properly/386130>\
**Category:** Kibana\
**Created:** [May 2, 2026, 1:52pm UTC](https://discuss.elastic.co/t/we-are-trying-to-configure-kibana-with-entra-id-azure-active-directory-and-it-is-not-working-properly/386130 "2026-05-02T13:52:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [May 2, 2026, 1:52pm UTC](https://discuss.elastic.co/t/we-are-trying-to-configure-kibana-with-entra-id-azure-active-directory-and-it-is-not-working-properly/386130/1 "2026-05-02T13:52:31Z")

</div>

Hello Everyone,

We are having a onprem cluster 8.17.x where we are trying to configure entra id for kibana login. unable to successfully do it. unfortunately we are not getting any logs in kibana or elk after the configuration. but we are unable to login to kibana. We have done sync between Entra id and made ur the roles and user mappings are in place.

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [May 2, 2026, 1:53pm UTC](https://discuss.elastic.co/t/we-are-trying-to-configure-kibana-with-entra-id-azure-active-directory-and-it-is-not-working-properly/386130/2 "2026-05-02T13:53:14Z")

</div>

I feel it might be an issue with the roles and mappings, where elk or kibana are unable to fetch the entra id roles .

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 2, 2026, 2:02pm UTC](https://discuss.elastic.co/t/we-are-trying-to-configure-kibana-with-entra-id-azure-active-directory-and-it-is-not-working-properly/386130/3 "2026-05-02T14:02:39Z")

</div>

Are you following this documentation here: [Set up SAML with Microsoft Entra ID | Elastic Docs](https://www.elastic.co/docs/deploy-manage/users-roles/cluster-or-deployment-auth/saml-entra) ?

Have you reached out to support yet? Since this is a paid feature you must have a license which comes with support as well.

---

<div class="post-metadata">

**Author:** ![AKAM14](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Post date:** [May 2, 2026, 2:19pm UTC](https://discuss.elastic.co/t/we-are-trying-to-configure-kibana-with-entra-id-azure-active-directory-and-it-is-not-working-properly/386130/4 "2026-05-02T14:19:09Z")

</div>

Yes, we have followed the docs. and reached out to support. Support team is not of much help. they are not engaging enough with us to resolve the issue

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 2, 2026, 5:30pm UTC](https://discuss.elastic.co/t/we-are-trying-to-configure-kibana-with-entra-id-azure-active-directory-and-it-is-not-working-properly/386130/5 "2026-05-02T17:30:13Z")

</div>

Hi @AKAM14

First did you know you can search the Knowledge Base Articles in the support portal, lots of good stuff there

I have debugged many SAML setups (not so much MS Entra)

But it usually comes down to a couple of things

1. The SAML URLs / Setup/ Configuration Is Incorrect. I always ask who is the SAML SME for your org you need that person to review the settings
2. There are connectivity issue between components
3. Role Mapping is incorrect.

So here is what I suggest

Turn On Logging in Elasticsearch at TRACE level, and you will see the very fine details of the flow and error messages.

The Below will turn on the low-level tracing ... Which node will handle these request, you will need to find that node

^^^ That's why I do ALL this testing on a single-node cluster before I try to take it to a multi-node. Also, using a single-node cluster also minimized restart time after changes to elasticsearch.yml (That's a pro-tip 🙂 )

This is the ONLY way to debug SAML as far as I am concerned.

```auto
PUT _cluster/settings
{
  "transient" : {
      "logger.org.elasticsearch.xpack.security.authc.saml" : "TRACE",
      "logger.org.elasticsearch.xpack.security.authz" : "TRACE"
  }
 }

```

To turn the above off

```auto
PUT _cluster/settings
{
  "transient" : {
      "logger.org.elasticsearch.xpack.security.authc.saml" : null,
      "logger.org.elasticsearch.xpack.security.authz" : null
  }
 }

```

also you can

Kibana Logging: Add `logging.verbose: true` to your `kibana.yml` file.

When you try to log in with the SAML ...  
You need to be tailing the logs, in the log there will be the detail that shows what fields are actually being passed to elastic or errors or both... Look at this carefully it will tell you exactly what is wrong

Fix any obvious errors and

Only THEN can you know how to set up the actual role mapping looking at what fields are being passed in

The next thing I do is set up a "wide open" role mapping to see if it works  
This will basically map anyone to super user

```auto
POST /_security/role_mapping/SAML_kibana
{
    "enabled": true,
    "roles": ["superuser"],
    "rules" : {
      "all" : [
        {
          "field" : {
            "realm.name" : "kibana-realm"
          }
        }
      ]
    },
    "metadata": { "version": 1 }
}

```

THEN if that works, and now that you can see what fields are actually being passed in from SAML then you can work on a real role mapping

```auto
POST /_security/role_mapping/SAML_kibana
{
    "enabled": true,
    "roles": ["superuser"],
    "rules" : {
      "all" : [
        {
          "field" : {
            "realm.name" : "kibana-realm"
          }
        },
        {
          "field" : {
            "group" : [
              "admin"
            ]
          }
        }
      ]
    },
    "metadata": { "version": 1 }
}

```

Hope this helps a bit
