# Can X-Pack be used entirely for application authentication and authorization

**URL:** <https://discuss.elastic.co/t/can-x-pack-be-used-entirely-for-application-authentication-and-authorization/90997>\
**Category:** Elasticsearch\
**Created:** [June 27, 2017, 4:25pm UTC](https://discuss.elastic.co/t/can-x-pack-be-used-entirely-for-application-authentication-and-authorization/90997 "2017-06-27T16:25:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![moraleslos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moraleslos/32/18527_2.png) [@moraleslos](https://discuss.elastic.co/u/moraleslos)\
**Post date:** [June 27, 2017, 4:25pm UTC](https://discuss.elastic.co/t/can-x-pack-be-used-entirely-for-application-authentication-and-authorization/90997/1 "2017-06-27T16:25:30Z")

</div>

For an app we are creating, we are still using .NET as middleware that includes authentication and authorization over RESTful services that essentially calls ES apis. Was wondering if X-Pack can essentially handle this tier in a similar fashion. For example, any registered users will have indexing permissions, while unregistered users will only have searching capabilities. It needs to be somewhat fine-grained as well in terms of what can be indexed.

If the above is possible using X-Pack with ES, we may eliminate the .NET middleware altogether since the heart of the app is through ES.

---

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [June 27, 2017, 11:57pm UTC](https://discuss.elastic.co/t/can-x-pack-be-used-entirely-for-application-authentication-and-authorization/90997/2 "2017-06-27T23:57:38Z")

</div>

This should be possible, but it will depend on what you're trying to do.

For example you can enable anonymous access with these instructions  
[https://www.elastic.co/guide/en/x-pack/current/anonymous-access.html](https://www.elastic.co/guide/en/x-pack/current/anonymous-access.html)

Then you would want to create roles for the other users giving them write access as needed.  
[https://www.elastic.co/guide/en/x-pack/current/authorization.html](https://www.elastic.co/guide/en/x-pack/current/authorization.html)

Depending on how fine grained you need the access to be will be the decider here. Write access is granted to an entire index. We lack the ability to do fine grained write access on a document level.

Good luck.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2017, 11:58pm UTC](https://discuss.elastic.co/t/can-x-pack-be-used-entirely-for-application-authentication-and-authorization/90997/3 "2017-07-25T23:58:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
