# AuthC for Kibana but not for ES

**URL:** <https://discuss.elastic.co/t/authc-for-kibana-but-not-for-es/144733>\
**Category:** Kibana\
**Created:** [August 16, 2018, 2:47pm UTC](https://discuss.elastic.co/t/authc-for-kibana-but-not-for-es/144733 "2018-08-16T14:47:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Steve\_Sonnenberg](https://avatars.discourse-cdn.com/v4/letter/s/a698b9/32.png) [@Steve\_Sonnenberg](https://discuss.elastic.co/u/Steve_Sonnenberg)\
**Post date:** [August 16, 2018, 2:47pm UTC](https://discuss.elastic.co/t/authc-for-kibana-but-not-for-es/144733/1 "2018-08-16T14:47:52Z")

</div>

I'd like to authenticate users for Kibana against AD, but not for ES (because its used for ingest).  
Is this possible?  
Having to set the xpack settings in elasticsearch.yml seems counter-intuitive if this is supported.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 17, 2018, 5:33am UTC](https://discuss.elastic.co/t/authc-for-kibana-but-not-for-es/144733/2 "2018-08-17T05:33:59Z")

</div>

Kibana uses Elasticsearch for its security enforcement - your Kibana users have privileges to ES data.  
You cannot have authentication in Kibana without enabling it in Elasticsearch.

You _might_ be able to patch something together using anonymous access in Elasticsearch, but I wouldn't recommend it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2018, 5:34am UTC](https://discuss.elastic.co/t/authc-for-kibana-but-not-for-es/144733/3 "2018-09-14T05:34:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
