# Anonymous/Auto authentification in Kibana

**URL:** <https://discuss.elastic.co/t/anonymous-auto-authentification-in-kibana/186897>\
**Category:** Kibana\
**Created:** [June 21, 2019, 2:19pm UTC](https://discuss.elastic.co/t/anonymous-auto-authentification-in-kibana/186897 "2019-06-21T14:19:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hyrastios](https://avatars.discourse-cdn.com/v4/letter/h/a3d4f5/32.png) [@Hyrastios](https://discuss.elastic.co/u/Hyrastios)\
**Post date:** [June 21, 2019, 2:19pm UTC](https://discuss.elastic.co/t/anonymous-auto-authentification-in-kibana/186897/1 "2019-06-21T14:19:18Z")

</div>

Hi,

I'm using a local 1 cluster 2 nodes 7.1.1 ELK setup with xpack security enabled on elasticsearch.  
What I want to do is setting up an auto-authentification or an anonymous access in order for the user to directly arrive on Kibana but as a read-only user, and then let him the possibility to login as a superuser in order to manage the data in the cluster.

I tried to follow the instruction on this [tutorial](https://www.elastic.co/guide/en/elastic-stack-overview/7.1/anonymous-access.html). Here is my ES setup :

```
xpack.security.authc:
  anonymous: 
    username: _es_anonymous_user
    roles: anonymous_user
    authz_exception: true

```

So I created an "anonymous\_user" role with read privilege on every ("\*") indices but it didn't change anything in Kibana nor in ES. I also tried to add "\_anonymous" in the run as privileges section but it didn't work either.

While searching solutions on the internet, I found this [topic](https://github.com/elastic/kibana/issues/18331). The last answer is 26 days old and the topic is still open, which let me think that the anonymous access as I want to implement, isn't yet available on the 7.1.1, whereas there is a documentation about it.

I also searched a few about the auto-authentification way, and the only solutions I found were using reverse proxys with nginx to work. Is there any other way which do not require an other server ?

Thanks guys for taking the time to answer me, and I'm sorry if my english is a bit approximative.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [June 21, 2019, 10:20pm UTC](https://discuss.elastic.co/t/anonymous-auto-authentification-in-kibana/186897/2 "2019-06-21T22:20:21Z")

</div>

Unfortunately anonymous access isn't well supported in Kibana right now. You can follow this ticket for more information [https://github.com/elastic/kibana/issues/35613](https://github.com/elastic/kibana/issues/35613)

At the moment, the only way to get anonymous access working while keeping security enabled is to put a reverse proxy in front of Kibana that will supply the basic auth header.

---

<div class="post-metadata">

**Author:** ![Hyrastios](https://avatars.discourse-cdn.com/v4/letter/h/a3d4f5/32.png) [@Hyrastios](https://discuss.elastic.co/u/Hyrastios)\
**Post date:** [June 24, 2019, 7:09am UTC](https://discuss.elastic.co/t/anonymous-auto-authentification-in-kibana/186897/3 "2019-06-24T07:09:43Z")

</div>

Thank you for your answer ! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 22, 2019, 7:09am UTC](https://discuss.elastic.co/t/anonymous-auto-authentification-in-kibana/186897/4 "2019-07-22T07:09:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
