# Setting up SAML with an admin group

**URL:** <https://forum.opensearch.org/t/setting-up-saml-with-an-admin-group/5552>\
**Category:** Security\
**Created:** [April 9, 2021, 10:50am UTC](https://forum.opensearch.org/t/setting-up-saml-with-an-admin-group/5552 "2021-04-09T10:50:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mr\_Hedgehog](https://avatars.discourse-cdn.com/v4/letter/m/74df32/32.png) [@Mr\_Hedgehog](https://forum.opensearch.org/u/Mr_Hedgehog)\
**Post date:** [April 9, 2021, 10:50am UTC](https://forum.opensearch.org/t/setting-up-saml-with-an-admin-group/5552/1 "2021-04-09T10:50:30Z")

</div>

Hello there,

I have been working to setup SAML and am pretty much there, but my understanding is that you lose access to the internal ‘admin’ user, once it has been setup.

With ODFE 1.12.0 (docker), via SAML, I can login as my user and can see my AD group membership passed back as the Role in the SAML assertion. I am a member of the AD group grp\_Elastic\_Admins.

I can successfully map that backend role to various system and user defined roles, eg kibana\_user, own\_index and some other custom roles, but I want to map that backend role to the all\_access role, so that being a member of grp\_Elastic\_Admins gives me the Security tab in Kibana (which is currently not visible).

I have the following config

```auto
all_access:
  reserved: false
  backend_roles:
  - "admin"
  - "grp_Elastic_Admins"
  description: "Maps admin to all_access"

```

I have tried reloading the config and rolesmapping via running securityadmin.sh but I cannot get kibana to recognise that I am mapped to the all\_access role.

Am I missing something fundamental here, or going about this the wrong way? Happy to provide snippets of config if this will help.

Thanks, Will.

---

<div class="post-metadata">

**Author:** ![Mr\_Hedgehog](https://avatars.discourse-cdn.com/v4/letter/m/74df32/32.png) [@Mr\_Hedgehog](https://forum.opensearch.org/u/Mr_Hedgehog)\
**Post date:** [April 10, 2021, 3:07pm UTC](https://forum.opensearch.org/t/setting-up-saml-with-an-admin-group/5552/2 "2021-04-10T15:07:13Z")

</div>

Should anyone else come across this - I have answered this myself.

The config was correct, however, as I am using docker and mapping individual files through to the container I don’t believe configs were being correctly pushed through, so securityconfig.sh was seeing cached old copies.
