Splunk Cloud

Splunk Cloud User Manual

Acrobat logo Download manual as PDF

Acrobat logo Download topic as PDF

Configure SAML single sign-on (SSO) to Splunk Cloud

Splunk Cloud lets you use SAML authentication for single sign-on (SSO).


  • A Splunk Cloud deployment.
  • An identity provider configured to provide the role, realName, and mail attributes.
  • An admin role with the change_authentication capability. This permission level lets you enable SAML and edit authentication settings on the Splunk Cloud search head.
  • If you require multifactor authentication, then you must use a SAML v2 identity provider that supports multifactor authentication. While Splunk Enterprise has built-in support for multifactor authentication such as Duo and RSA, Splunk Cloud does not support these methods of integration.
  • Only SHA-256 signatures in the SAML message between your IdP and Splunk Cloud are supported. You are responsible for the SAML configuration of your IdP including the use of SHA-256 signatures.
  • For ADFS, you may need to set the Claim Type as "UPN" when configuring your IdP. The Splunk blog post at https://www.splunk.com/blog/2016/09/14/configuring-microsofts-adfs-splunk-cloud.html provides more information about configuring ADFS for Cloud.

When you configure Splunk Cloud to use your SAML authentication system, you must authorize groups on your SAML server to log in by mapping them to Splunk Cloud roles. To enable SSO, use information provided by your identity provider to configure Splunk Cloud to work with SAML. For details, see Configure single sign-on with SAML in the Securing Splunk Cloud manual.

Last modified on 05 May, 2021
Set limits for concurrent scheduled searches
Configure hybrid search

This documentation applies to the following versions of Splunk Cloud: 8.1.2103, 8.2.2104

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters