Configure single sign-on
Use Microsoft Entra ID single sign-on to authenticate organization users to Kibana.
Platform SSO configuration is performed through the iVedha AI chat:
https://copilot.opsflw.io
Microsoft Entra authenticates the user. Elastic roles and role mappings determine what the authenticated user can access.
Before you begin
Coordinate with:
- a Microsoft Entra application administrator;
- an Elastic security administrator.
You will need:
- your Microsoft Entra tenant ID;
- an Entra application registration;
- the application client ID;
- a client credential;
- the redirect URI provided for your deployment;
- the Entra groups that will be mapped to Elastic roles.
Do not create the redirect URI from examples or naming conventions. Use the exact value provided for your deployment.
Register the application in Microsoft Entra
In Microsoft Entra:
- Open App registrations.
- Create an application registration for the Elastic platform.
- Configure the application as required by your organization's identity policy.
- Add the exact Web redirect URI provided for the deployment.
- Create the client credential required for the integration.
- Configure the user and group claims required for access mapping.
Store the client secret securely.
Do not place the client secret in documentation, tickets, email, or screenshots.
Configure SSO through iVedha AI chat
- Sign in to:
https://copilot.opsflw.io
- Select or identify the deployment.
- Ask the assistant to configure single sign-on or Microsoft Entra OIDC.
- Complete identity verification when requested.
- Provide the requested Entra configuration values.
- Provide the client credential only through the protected credential workflow.
- Review and confirm the requested change.
- Wait for the platform to apply and synchronize the SSO configuration.
Allow a few minutes for the configuration to become active.
Map Entra groups to Elastic roles
Successful authentication does not automatically grant access to Elasticsearch or Kibana.
Create the required Elastic roles, then map approved Microsoft Entra groups to those roles.
Typical mappings can provide:
- read-only access;
- dashboard access;
- data administration;
- platform administration.
Use least-privilege mappings and avoid assigning broad administrative access to all authenticated users.
Test single sign-on
Test with a normal user account before relying on SSO for administrative access.
Confirm that:
- opening Kibana redirects the user to Microsoft Entra;
- authentication completes successfully;
- the user returns to Kibana;
- the user can access only the intended Kibana spaces and Elasticsearch data;
- a user without an approved role mapping does not receive unintended access.
Keep the administrator credential available until SSO has been fully validated.
Application and API access
OIDC SSO is primarily intended for interactive Kibana users.
Applications, integrations, and Elasticsearch REST clients should use an appropriate supported credential such as an API key rather than an interactive SSO login.
If SSO does not work
Common causes include:
| Symptom | Check |
|---|---|
| Entra reports a redirect URI mismatch | Confirm the exact deployment-provided redirect URI is registered |
| Authentication succeeds but Kibana denies access | Check Entra group claims and Elastic role mappings |
| Authentication fails after credential rotation | Confirm the active client credential and allow time for synchronization |
| User repeatedly returns to the sign-in page | Check the Entra application configuration and deployment SSO settings |
| Some users do not receive expected group access | Confirm the required group claims are present |
For assistance:
- AI chat:
https://copilot.opsflw.io - Support portal:
https://support.ivedha.com/
Provide the deployment reference from your Your deployment is ready notification.
Next step
After SSO is working, continue with data onboarding.