# Disallow change password of other users

**URL:** <https://discuss.elastic.co/t/disallow-change-password-of-other-users/189255>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [July 7, 2019, 4:06pm UTC](https://discuss.elastic.co/t/disallow-change-password-of-other-users/189255 "2019-07-07T16:06:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![koriyen](https://avatars.discourse-cdn.com/v4/letter/k/bbe5ce/32.png) [@koriyen](https://discuss.elastic.co/u/koriyen)\
**Post date:** [July 7, 2019, 4:06pm UTC](https://discuss.elastic.co/t/disallow-change-password-of-other-users/189255/1 "2019-07-07T16:06:37Z")

</div>

Hello.

I would like to create a role that allows creating new users and manage them. But, it must not be able to change the password / manage some specific users.

Is this possible?.

The idea is 2 layers of administration:

- super admin: It manages all the users (built-in, logstash, kibana, etc).
- admin: It manages new users, but it shouldn't be able to modify the users created by the super admin user.

Thanks.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 8, 2019, 3:04am UTC](https://discuss.elastic.co/t/disallow-change-password-of-other-users/189255/2 "2019-07-08T03:04:42Z")

</div>

No this is not possible.

You can have a role which allows you to create / modify users but not change their passwords. However you cannot segment your users, and place limits on which users can be modified by which role.

---

<div class="post-metadata">

**Author:** ![koriyen](https://avatars.discourse-cdn.com/v4/letter/k/bbe5ce/32.png) [@koriyen](https://discuss.elastic.co/u/koriyen)\
**Post date:** [July 8, 2019, 3:09pm UTC](https://discuss.elastic.co/t/disallow-change-password-of-other-users/189255/3 "2019-07-08T15:09:51Z")

</div>

> You can have a role which allows you to create / modify users but not change their passwords.

What is that role?. If I set the role _manage\_security_, I can modify other users and their passwords.

Thanks.

---

<div class="post-metadata">

**Author:** ![koriyen](https://avatars.discourse-cdn.com/v4/letter/k/bbe5ce/32.png) [@koriyen](https://discuss.elastic.co/u/koriyen)\
**Post date:** [July 9, 2019, 10:06am UTC](https://discuss.elastic.co/t/disallow-change-password-of-other-users/189255/4 "2019-07-09T10:06:05Z")

</div>

Any update?.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2019, 10:06am UTC](https://discuss.elastic.co/t/disallow-change-password-of-other-users/189255/5 "2019-08-06T10:06:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
