# Adding multiple new LDAP/Active Directory realms on the fly

**URL:** <https://discuss.elastic.co/t/adding-multiple-new-ldap-active-directory-realms-on-the-fly/75507>\
**Category:** Elasticsearch\
**Created:** [February 17, 2017, 2:11pm UTC](https://discuss.elastic.co/t/adding-multiple-new-ldap-active-directory-realms-on-the-fly/75507 "2017-02-17T14:11:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ljacobs](https://avatars.discourse-cdn.com/v4/letter/l/b9bd4f/32.png) [@ljacobs](https://discuss.elastic.co/u/ljacobs)\
**Post date:** [February 17, 2017, 2:11pm UTC](https://discuss.elastic.co/t/adding-multiple-new-ldap-active-directory-realms-on-the-fly/75507/1 "2017-02-17T14:11:50Z")

</div>

Hi all,

I am currently looking to x-pack and the elastic stack to implement a kind of User Management system, where there will be multiple external "companies" signing up and linking their own external ldap servers/active directories.

I've been looking through the documentation around [ldap](https://www.elastic.co/guide/en/x-pack/current/ldap-realm.html) and [active directory](https://www.elastic.co/guide/en/x-pack/current/active-directory-realm.html) realms, and have two main concerns.

1. The documentation mentions that an ElasticSearch restart is required when configuring a new realm, this doesn't sound optimal for my use case where a new "company" can link or de-link their active directory at any time.
2. As order is specified in the configuration, this implies to me that if I have 100 active directories linked, users in active directory 100 will have first had their details checked in the other 99 repositories.

Is there a better method for setting up this kind of use case, where any number of external active directories/ldap repositories can be added and queried on the fly?

Cheers,  
Lewis

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 18, 2017, 10:15pm UTC](https://discuss.elastic.co/t/adding-multiple-new-ldap-active-directory-realms-on-the-fly/75507/2 "2017-02-18T22:15:25Z")

</div>

Those are the limitations when you want to deploy in this sort of setup.

You could abstract things into the native (API) realm.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2017, 10:15pm UTC](https://discuss.elastic.co/t/adding-multiple-new-ldap-active-directory-realms-on-the-fly/75507/3 "2017-03-18T22:15:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
