# Cannot get AD auth to work with Trial license

**URL:** <https://discuss.elastic.co/t/cannot-get-ad-auth-to-work-with-trial-license/244706>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 12, 2020, 11:49am UTC](https://discuss.elastic.co/t/cannot-get-ad-auth-to-work-with-trial-license/244706 "2020-08-12T11:49:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hazcod](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hazcod/32/67689_2.png) [@hazcod](https://discuss.elastic.co/u/hazcod)\
**Post date:** [August 12, 2020, 11:49am UTC](https://discuss.elastic.co/t/cannot-get-ad-auth-to-work-with-trial-license/244706/1 "2020-08-12T11:49:59Z")

</div>

Hi, I am trying to setup Active Directory authentication for my elastic 7.80 stack.  
The steps i've taken:

1. Enable trial license
2. Put my ldaps certificate in /etc/elasticsearch/ad-ca.pem
3. Configure ldaps realm in elasticsearch.yml:

```auto
xpack.security.authc.realms:
  active_directory:
   myad:
     order: 0
     domain_name: company.com
     url: ldaps://company.com:636
     ssl:
        verification_mode: certificate
        certificate_authorities: ["/etc/elasticsearch/ad-ca.pem"]

```

1. Configure my role mapping in role\_mapping.yml:

```auto
superuser:
- "cn=myteam,ou=DGroups,ou=Groups,ou=BE,dc=company,dc=com"

```

However authentication will always fail for AD credentials when I try it locally on the machine:

```auto
curl --cacert ~/ca.pem –u ‘user:pass’ https://127.0.0.1:9200/

{"error":{"root_cause":[{"type":"security_exception","reason":"action [cluster:monitor/main] is unauthorized for user [user]"}],"type":"security_exception","reason":"action [cluster:monitor/main] is unauthorized for user [user]"},"status":403}

```

But when I try this PowerShell cmdleton my work laptop, the query should work since this lists all my colleagues:

```auto
Get-ADUser -LDAPFilter '(memberof=cn=myteam,ou=DGroups,ou=Groups,ou=BE,dc=company,dc=com)'
...

```

I have the same issue if I use `memberOf` in `role_mapping.yml`:

```auto
superuser:
- "(memberOf=cn=myteam,ou=DGroups,ou=Groups,ou=BE,dc=company,dc=com)"

```

---

<div class="post-metadata">

**Author:** ![hazcod](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hazcod/32/67689_2.png) [@hazcod](https://discuss.elastic.co/u/hazcod)\
**Post date:** [August 13, 2020, 1:34pm UTC](https://discuss.elastic.co/t/cannot-get-ad-auth-to-work-with-trial-license/244706/2 "2020-08-13T13:34:22Z")

</div>

I just noticed that we do not have `security groups` in our AD, but only distribution groups.  
So I'ld like to supply queries for separate users instead.

When trying a user query, this also does not work:

```auto
superuser:
- "cn=myuser,ou=department,ou=Users,ou=BE,dc=company,dc=com"

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 14, 2020, 8:51pm UTC](https://discuss.elastic.co/t/cannot-get-ad-auth-to-work-with-trial-license/244706/3 "2020-08-14T20:51:01Z")

</div>

See [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/active-directory-realm.html) , we only support security groups for authorization purposes, not distribution groups

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 15, 2020, 6:08am UTC](https://discuss.elastic.co/t/cannot-get-ad-auth-to-work-with-trial-license/244706/4 "2020-08-15T06:08:11Z")

</div>

> [@hazcod](#):
>
> When trying a user query, this also does not work:

We need more information than that. What behaviour do you see?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 12, 2020, 6:08am UTC](https://discuss.elastic.co/t/cannot-get-ad-auth-to-work-with-trial-license/244706/5 "2020-09-12T06:08:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
