# After selecting App Search, I can no longer select Workplace Search

**URL:** <https://discuss.elastic.co/t/after-selecting-app-search-i-can-no-longer-select-workplace-search/270629>\
**Category:** Elastic Search\
**Created:** [April 19, 2021, 9:41pm UTC](https://discuss.elastic.co/t/after-selecting-app-search-i-can-no-longer-select-workplace-search/270629 "2021-04-19T21:41:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [April 19, 2021, 9:41pm UTC](https://discuss.elastic.co/t/after-selecting-app-search-i-can-no-longer-select-workplace-search/270629/1 "2021-04-19T21:41:34Z")

</div>

When I logged into Enterprise Search via my AD/ES-Native user, I was given the option to choose either App Search or Workplace Search. I selected App Search. Now, when I go back to `/ent/select`, Workplace Search no longer shows up as an option.

If I hit `/ws`, I get redirected to `/as`.

If I log in via the elastic super user, I can switch just fine.

I have a trial going on my Elasticsearch cluster, so I should have access to all features. So lack of a license shouldn't be the problem.

Would the fact I don't have any WS sources configured yet have something to do with it?

Any other ideas?

Edit:  
This is all on version 7.12.

I have enterprise search configured to use elasticsearch-native for auth, and ES is configured to use AD.

---

<div class="post-metadata">

**Author:** ![JonasLavoie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonaslavoie/32/56961_2.png) [@JonasLavoie](https://discuss.elastic.co/u/JonasLavoie)\
**Post date:** [April 20, 2021, 1:38am UTC](https://discuss.elastic.co/t/after-selecting-app-search-i-can-no-longer-select-workplace-search/270629/2 "2021-04-20T01:38:01Z")

</div>

Heya David!

Let's get this sorted out together. It appears that role mappings are at play here. Did you manually apply role mappings in the App Search interfaces for the AD-Native user using the superadmin? Perhaps even via the Workplace Search Role Mappings UI?

---

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [April 20, 2021, 3:23pm UTC](https://discuss.elastic.co/t/after-selecting-app-search-i-can-no-longer-select-workplace-search/270629/3 "2021-04-20T15:23:54Z")

</div>

Nope. I just double checked. There's a nice big "No Role Mappings yet" message on the App Search Users & Roles screen.

I'm using the Elasticsearch Ansible role to manage roles via the file based system. The user in question is mapped to the "users" role via an AD group.

---

<div class="post-metadata">

**Author:** ![JonasLavoie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonaslavoie/32/56961_2.png) [@JonasLavoie](https://discuss.elastic.co/u/JonasLavoie)\
**Post date:** [April 20, 2021, 4:01pm UTC](https://discuss.elastic.co/t/after-selecting-app-search-i-can-no-longer-select-workplace-search/270629/4 "2021-04-20T16:01:32Z")

</div>

And using the superuser, can you confirm that no role mapping exist in the Workplace Search Role Mappings UI please?

---

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [April 20, 2021, 4:30pm UTC](https://discuss.elastic.co/t/after-selecting-app-search-i-can-no-longer-select-workplace-search/270629/5 "2021-04-20T16:30:06Z")

</div>

![Screenshot_2021-04-20 Elastic Workplace Search](https://us1.discourse-cdn.com/elastic/original/3X/8/0/808d7028a0cf98b52e37721799578c0b64e1516a.png)  
That is what I have set for Workplace search.

---

<div class="post-metadata">

**Author:** ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Post date:** [April 20, 2021, 7:58pm UTC](https://discuss.elastic.co/t/after-selecting-app-search-i-can-no-longer-select-workplace-search/270629/6 "2021-04-20T19:58:30Z")

</div>

FYI, I deleted the two email mappings, then added one based on an ES Native role. That let my normal user start switching between the two tools.

---

<div class="post-metadata">

**Author:** ![JonasLavoie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonaslavoie/32/56961_2.png) [@JonasLavoie](https://discuss.elastic.co/u/JonasLavoie)\
**Post date:** [April 20, 2021, 8:20pm UTC](https://discuss.elastic.co/t/after-selecting-app-search-i-can-no-longer-select-workplace-search/270629/7 "2021-04-20T20:20:55Z")

</div>

Awesome - glad you managed to narrow it down - role mappings can be tricky at times. Another thing to keep in mind is if you want to make sure end-users do not have access to one of the two products, you must create at least one role mapping in the product to be restricted (in general, declaratively mapping the superuser to an admin role will do).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:29am UTC](https://discuss.elastic.co/t/after-selecting-app-search-i-can-no-longer-select-workplace-search/270629/8 "2022-11-04T08:29:09Z")

</div>


