# Active Directory user authentication

**URL:** <https://discuss.elastic.co/t/active-directory-user-authentication/265053>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 22, 2021, 10:36am UTC](https://discuss.elastic.co/t/active-directory-user-authentication/265053 "2021-02-22T10:36:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![AayushPatel](https://avatars.discourse-cdn.com/v4/letter/a/da6949/32.png) [@AayushPatel](https://discuss.elastic.co/u/AayushPatel)\
**Post date:** [February 22, 2021, 10:36am UTC](https://discuss.elastic.co/t/active-directory-user-authentication/265053/1 "2021-02-22T10:36:44Z")

</div>

Hi, we need to use Elasticsearch authentication for our users in DC (Active Directory).  
Due to the instructs in link below:  
[https://www.elastic.co/guide/en/elasticsearch/reference/7.11/active-directory-realm.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.11/active-directory-realm.html)  
I add the AD realm to elasticsearch.yml

```auto
xpack:
  security:
    authc:
      realms:
        active_directory:
          my_ad:
            order: 0
            domain_name: develop.local
            url: ldap://192.168.3.89:389
            user_search:
              base_dn: "cn=users,dc=develop,dc=local"
            group_search:
              base_dn: "cn=users,dc=develop,dc=local"
            files:
              role_mapping: "/etc/elasticsearch/role_mapping.yml"

```

and this line to role\_mapping.yaml

```auto
superuser:
  - "cn=elasticsearch-superuser,cn=users,dc=develop,dc=local"

```

but we can not log in elasticsearch not with local users, nor users of domain controller.  
and get this as elasticsearch log

```auto
[2021-02-22T05:15:21,458][WARN][o.e.x.s.a.AuthenticationService] [APK-Elastic-Node] Authentication to realm my_ad failed - authenticate failed (Caused by LDAPException(resultCode=49 (invalid credentials), diagnosticMessage='80090308: LdapErr: DSID-0C09041C, comment: AcceptSecurityContext error, data 52e, v4563', ldapSDKVersion=4.0.8, revision=28812))
[2021-02-22T05:15:21,913][WARN][o.e.x.s.a.AuthenticationService] [APK-Elastic-Node] Authentication to realm my_ad failed - authenticate failed (Caused by LDAPException(resultCode=49 (invalid credentials), diagnosticMessage='80090308: LdapErr: DSID-0C09041C, comment: AcceptSecurityContext error, data 52e, v4563', ldapSDKVersion=4.0.8, revision=28812))
[2021-02-22T05:15:24,406][WARN][o.e.x.s.a.AuthenticationService] [APK-Elastic-Node] Authentication to realm my_ad failed - authenticate failed (Caused by LDAPException(resultCode=49 (invalid credentials), diagnosticMessage='80090308: LdapErr: DSID-0C09041C, comment: AcceptSecurityContext error, data 52e, v4563', ldapSDKVersion=4.0.8, revision=28812))
[2021-02-22T05:15:24,456][WARN][o.e.x.s.a.AuthenticationService] [APK-Elastic-Node] Authentication to realm my_ad failed - authenticate failed (Caused by LDAPException(resultCode=49 (invalid credentials), diagnosticMessage='80090308: LdapErr: DSID-0C09041C, comment: AcceptSecurityContext error, data 52e, v4563', ldapSDKVersion=4.0.8, revision=28812))
[2021-02-22T05:15:26,905][WARN][o.e.x.s.a.AuthenticationService] [APK-Elastic-Node] Authentication to realm my_ad failed - authenticate failed (Caused by LDAPException(resultCode=49 (invalid credentials), diagnosticMessage='80090308: LdapErr: DSID-0C09041C, comment: AcceptSecurityContext error, data 52e, v4563', ldapSDKVersion=4.0.8, revision=28812))
[2021-02-22T05:15:27,463][WARN][o.e.x.s.a.AuthenticationService] [APK-Elastic-Node] Authentication to realm my_ad failed - authenticate failed (Caused by LDAPException(resultCode=49 (invalid credentials), diagnosticMessage='80090308: LdapErr: DSID-0C09041C, comment: AcceptSecurityContext error, data 52e, v4563', ldapSDKVersion=4.0.8, revision=28812))
[2021-02-22T05:15:29,406][WARN][o.e.x.s.a.AuthenticationService] [APK-Elastic-Node] Authentication to realm my_ad failed - authenticate failed (Caused by LDAPException(resultCode=49 (invalid credentials), diagnosticMessage='80090308: LdapErr: DSID-0C09041C, comment: AcceptSecurityContext error, data 52e, v4563', ldapSDKVersion=4.0.8, revision=28812))

```

I have a group named elasticsearch-superuser in AD and two users (members of elasticsearch-superuser)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 22, 2021, 10:41am UTC](https://discuss.elastic.co/t/active-directory-user-authentication/265053/2 "2021-02-22T10:41:37Z")

</div>

What type of license are you using? According to [the docs](https://www.elastic.co/subscriptions) AD integration requires a commercial license (Gold or above).

---

<div class="post-metadata">

**Author:** ![AayushPatel](https://avatars.discourse-cdn.com/v4/letter/a/da6949/32.png) [@AayushPatel](https://discuss.elastic.co/u/AayushPatel)\
**Post date:** [February 22, 2021, 2:02pm UTC](https://discuss.elastic.co/t/active-directory-user-authentication/265053/3 "2021-02-22T14:02:39Z")

</div>

we have a Platinum.  
the AD users problem solved with set

```auto
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters\ldapserverintegrity

```

value from 2 to 1  
but we do not have the built-in users yet. Is it normal that all the auth request go to AD realm or not?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 22, 2021, 11:31pm UTC](https://discuss.elastic.co/t/active-directory-user-authentication/265053/4 "2021-02-22T23:31:21Z")

</div>

> [@AayushPatel](#):
>
> we have a Platinum.

Then please also do raise a request with the Support team 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2021, 11:32pm UTC](https://discuss.elastic.co/t/active-directory-user-authentication/265053/5 "2021-03-22T23:32:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
