# Disallow change own password

**URL:** <https://discuss.elastic.co/t/disallow-change-own-password/78347>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 13, 2017, 1:43pm UTC](https://discuss.elastic.co/t/disallow-change-own-password/78347 "2017-03-13T13:43:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![slinky](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/slinky/32/13323_2.png) [@slinky](https://discuss.elastic.co/u/slinky)\
**Post date:** [March 13, 2017, 1:43pm UTC](https://discuss.elastic.co/t/disallow-change-own-password/78347/1 "2017-03-13T13:43:11Z")

</div>

I am going to share a (read-only) user with the world so people can check out my X-Pack demo.  
Therefore I need to disallow/disable the 'change password' option under the users own account options.  
Is this possible?

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [March 14, 2017, 4:12pm UTC](https://discuss.elastic.co/t/disallow-change-own-password/78347/2 "2017-03-14T16:12:45Z")

</div>

There isn't an explicit option for that today, though there are a few workarounds that may be sufficient for your needs.

1. We don't allow changing the password for AD/LDAP users, so if you have an AD/LDAP domain, you could create/use a shared user there.
2. You could configure a separate Kibana instance and configure anonymous access. There are a few ways to do this, which I actually just outlined in a recent post [I want authentication only for ES, not Kibana dashboards](https://discuss.elastic.co/t/i-want-authentication-only-for-es-not-kibana-dashboards/78553)

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 14, 2017, 9:02pm UTC](https://discuss.elastic.co/t/disallow-change-own-password/78347/3 "2017-03-14T21:02:12Z")

</div>

> [@skearns](#):
>
> We don't allow changing the password for AD/LDAP users, so if you have an AD/LDAP domain, you could create/use a shared user there.

It would also be possible to use the `file` realm for this (it doesn't support API-based password changes either).  
If you go down this path, please make sure you read the "IMPORTANT" notices in the [file realm documentation](https://www.elastic.co/guide/en/x-pack/current/file-realm.html) as there are key steps that you need to follow when setting up file-based authentication.

---

<div class="post-metadata">

**Author:** ![slinky](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/slinky/32/13323_2.png) [@slinky](https://discuss.elastic.co/u/slinky)\
**Post date:** [April 4, 2017, 11:36am UTC](https://discuss.elastic.co/t/disallow-change-own-password/78347/4 "2017-04-04T11:36:29Z")

</div>

Thanks for the answers.  
I also found a workaround myself:  
Using NGINX as reverse proxy to deny/drop the following requests:

```
location /api/security/v1/users/<user>/password {
                limit_except GET {
                        deny all;
                }
        }
 location /api/console/ {
                limit_except GET {
                        deny all;
                }
        }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2017, 11:36am UTC](https://discuss.elastic.co/t/disallow-change-own-password/78347/5 "2017-05-02T11:36:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
