# Customer-Specific Data Access in Elasticsearch for Integrated Kibana Dashboards

**URL:** <https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295>\
**Category:** Kibana\
**Created:** [February 28, 2024, 6:15am UTC](https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295 "2024-02-28T06:15:16Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Usama\_Tariq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usama_tariq/32/119820_2.png) [@Usama\_Tariq](https://discuss.elastic.co/u/Usama_Tariq)\
**Post date:** [February 28, 2024, 6:15am UTC](https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295/1 "2024-02-28T06:15:16Z")

</div>

Hello Elastic Community,

Our data model in Elasticsearch contains orders data from various brands. Our goal is to seamlessly embed the Kibana dashboard into our web application while ensuring that users do not encounter the Kibana login screen and can only view data pertinent to their brand.

Your expertise and experiences are highly valued, and I appreciate any assistance you can provide in navigating this challenge.

Thank you for your support!

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [February 28, 2024, 7:24am UTC](https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295/2 "2024-02-28T07:24:46Z")

</div>

Hi @Usama_Tariq,

It is possible to embed Kibana dashboards into your web application using an iframe and public URLs from Kibana. [This blog](https://www.elastic.co/blog/how-to-embed-kibana-dashboards) gives a good overview of the steps. It covers use of anonymous authentication to bypass the login screen, which is available as a free feature. Otherwise you can also make use of SSO if you have an Enterprise or above licence.

If you have any particular questions about the approach or your specific use case do let us know.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![Usama\_Tariq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usama_tariq/32/119820_2.png) [@Usama\_Tariq](https://discuss.elastic.co/u/Usama_Tariq)\
**Post date:** [February 28, 2024, 12:59pm UTC](https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295/3 "2024-02-28T12:59:43Z")

</div>

With anonymous access there can be only one user with specific roles. How it could help in managing data access for multiple users?  
Could you please elaborate on SSO? I think to leverage that there would be a need to create separate role mappings?  
Please correct me if I am wrong anywhere.

Thanks again for the help and quick response.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [February 28, 2024, 1:10pm UTC](https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295/4 "2024-02-28T13:10:23Z")

</div>

I don't think that's right that you can only specify one user for anonymous authentication. There is an example here with [2 SAML auth providers for example](https://www.elastic.co/guide/en/kibana/8.12/kibana-authentication.html#multiple-authentication-providers). I believe you can specify multiple anonymous providers and then use the `auth_provider_hint` to specify the providers. I don't know how many distinct user groups you need, and having more than a few or many that regularly change could make maintaining the provider config challenging, but it is possible.

For SSO there are details on setup [here](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#saml) in the documentation.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![Usama\_Tariq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usama_tariq/32/119820_2.png) [@Usama\_Tariq](https://discuss.elastic.co/u/Usama_Tariq)\
**Post date:** [February 29, 2024, 8:53am UTC](https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295/5 "2024-02-29T08:53:31Z")

</div>

Thank you for the explanation and reference links.  
So, for anonymous access I would need to create multiple providers under `xpack.security.authc.providers` setting in `kibana.yml` with users having roles with respect to their data access and pass `auth_provider_hint` paramter in iframe code?  
I'll look through the SSO documentation and revert back in case of any query.  
Thanks again!

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [February 29, 2024, 12:04pm UTC](https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295/6 "2024-02-29T12:04:41Z")

</div>

> [@Usama\_Tariq](#):
>
> So, for anonymous access I would need to create multiple providers under `xpack.security.authc.providers` setting in `kibana.yml` with users having roles with respect to their data access and pass `auth_provider_hint` paramter in iframe code?

Yes that's right. If you have any issues let us know.

---

<div class="post-metadata">

**Author:** ![Usama\_Tariq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usama_tariq/32/119820_2.png) [@Usama\_Tariq](https://discuss.elastic.co/u/Usama_Tariq)\
**Post date:** [February 29, 2024, 1:57pm UTC](https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295/7 "2024-02-29T13:57:00Z")

</div>

Could you please share a sample config for adding multiple anonymous users in yml? I have created users and roles already in Kibana. Need to apply config changes inside yml files on elastic cloud console.  
Thankyou.

---

<div class="post-metadata">

**Author:** ![Usama\_Tariq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usama_tariq/32/119820_2.png) [@Usama\_Tariq](https://discuss.elastic.co/u/Usama_Tariq)\
**Post date:** [February 29, 2024, 6:12pm UTC](https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295/8 "2024-02-29T18:12:27Z")

</div>

My understanding till now is that we can specify multiple anonymous users with roles (data access managed via index privileges or managed through query in role configuration) in elastic or kibana yml files. Then we can pass information as parameter for that anonymous user in the iframe code.  
In my case I can have multiple iframes based on the number of users and brands etc.  
Need some help here with configs or guide on how to achieve above  
Thanks.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [March 1, 2024, 6:54am UTC](https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295/9 "2024-03-01T06:54:13Z")

</div>

By config do you mean the `kibana.yml` config specifying the providers? So taking the [above SAML example](https://www.elastic.co/guide/en/kibana/8.12/kibana-authentication.html#multiple-authentication-providers) I mentioned previously as a baseline, I would expect it to look something like this:

```auto
xpack.security.loginHelp: " **Help** info with a [link](...)"
xpack.security.authc.providers:
  basic.basic1:
    order: 0
    icon: "logoElasticsearch"
    hint: "Typically for administrators"
  anonymous.anonymous1:
    order: 0
    credentials:
      username: "anonymous_service_account"
      password: "anonymous_service_account_password"
  anonymous.anonymous2:
    order: 1
    credentials:
      username: "another_anonymous_service_account"
      password: "another_anonymous_service_account_password"
  kerberos.kerberos1:
    order: 3
    enabled: false

```

---

<div class="post-metadata">

**Author:** ![Usama\_Tariq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usama_tariq/32/119820_2.png) [@Usama\_Tariq](https://discuss.elastic.co/u/Usama_Tariq)\
**Post date:** [March 1, 2024, 11:06am UTC](https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295/10 "2024-03-01T11:06:43Z")

</div>

I have used the following config in `kibana.yml` on cloud console, but changes have failed, causing Kibana to be in unhealthy state.

```auto
xpack.security.authc.providers:
  basic.basic1:
    order: 0
  anonymous.anonymous1:
    order: 0
    credentials:
      username: "anonymous_user_1_username"
      password: "anonymous_user_1_password"
  anonymous.anonymous2:
    order: 1
    credentials:
      username: "anonymous_user_2_username"
      password: "anonymous_user_2_password"

----- Expect to add config for more anonymous users as above, and to be passed in iframe code -----

```

Can you please help here? Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2024, 11:07am UTC](https://discuss.elastic.co/t/customer-specific-data-access-in-elasticsearch-for-integrated-kibana-dashboards/354295/11 "2024-03-29T11:07:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
