# Deny login to kibana to any user not in role\_mapping

**URL:** <https://discuss.elastic.co/t/deny-login-to-kibana-to-any-user-not-in-role-mapping/94362>\
**Category:** Kibana\
**Created:** [July 24, 2017, 4:09pm UTC](https://discuss.elastic.co/t/deny-login-to-kibana-to-any-user-not-in-role-mapping/94362 "2017-07-24T16:09:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cornoualis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cornoualis/32/23246_2.png) [@Cornoualis](https://discuss.elastic.co/u/Cornoualis)\
**Post date:** [July 24, 2017, 4:09pm UTC](https://discuss.elastic.co/t/deny-login-to-kibana-to-any-user-not-in-role-mapping/94362/1 "2017-07-24T16:09:00Z")

</div>

Hi,

I just configured security to interact with my AD.  
I discovered that any user (someone not in role\_mapping.yml) can login to kibana.  
Of course, he won't be able to to anything in it, but he can still reach the interface.

Is there a way to avoid it?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [July 24, 2017, 6:53pm UTC](https://discuss.elastic.co/t/deny-login-to-kibana-to-any-user-not-in-role-mapping/94362/2 "2017-07-24T18:53:27Z")

</div>

It's a current limitation of Kibana and the Security plugin. A user without the `kibana_user` role (the default, so that's the case you're seeing) will still be able to log in, but they won't be able to interact with anything. Every page will show a permissions error message, but nothing stops them from logging in.

There's some discussion happening right now to figure out how to stop the user from being able to log in in the first place, but it's a known limitation right now.

---

<div class="post-metadata">

**Author:** ![Cornoualis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cornoualis/32/23246_2.png) [@Cornoualis](https://discuss.elastic.co/u/Cornoualis)\
**Post date:** [July 25, 2017, 12:18pm UTC](https://discuss.elastic.co/t/deny-login-to-kibana-to-any-user-not-in-role-mapping/94362/3 "2017-07-25T12:18:52Z")

</div>

Thank you Joe!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2017, 12:18pm UTC](https://discuss.elastic.co/t/deny-login-to-kibana-to-any-user-not-in-role-mapping/94362/4 "2017-08-22T12:18:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
