Splunk Cloud

Splunk Cloud User Manual

Download manual as PDF

Download topic as PDF

Configure SAML single sign-on (SSO) to Splunk Cloud

Splunk Cloud lets you use SAML authentication for single sign-on (SSO).


  • A managed deployment of Splunk Cloud. Self-service deployments log in through the Splunk customer portal and cannot independently configure SAML SSO.
  • An identity provider configured to provide the role, realName, and mail attributes. Currently, Ping Identity, Okta, Azure AD, and ADFS are the only supported identity providers. If you need help configuring your identity provider, refer to your identity provider's documentation or support resource.
  • An admin role with the change_authentication capability. This permission level lets you enable SAML and edit authentication settings on the Splunk Cloud search head.
  • For AD FS, you may need to set the Claim Type as "UPN" when configuring your IdP. The Splunk blog post at https://www.splunk.com/blog/2016/09/14/configuring-microsofts-adfs-splunk-cloud.html provides more information about configuring AD FS for Cloud.

When you configure Splunk Cloud to use your SAML authentication system, you can authorize groups on your SAML server to log in by mapping them to Splunk Cloud roles. To enable SSO, use information provided by your identity provider to configure Splunk Cloud to work with SAML. For details, see Configure single sign-on with SAML in the Securing Splunk Enterprise manual.

Manage Splunk Cloud users and roles
Configure hybrid search

This documentation applies to the following versions of Splunk Cloud: 6.6.3, 7.0.0, 7.0.2, 7.0.3, 7.0.5, 7.0.8, 7.0.11, 7.1.3, 7.1.6, 7.2.3, 7.2.4, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 8.0.0

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters