# Elasticsearch Active Directory Authorization only support

**URL:** <https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080>\
**Category:** Elasticsearch\
**Created:** [May 25, 2017, 7:56am UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080 "2017-05-25T07:56:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![him117](https://avatars.discourse-cdn.com/v4/letter/h/cab0a1/32.png) [@him117](https://discuss.elastic.co/u/him117)\
**Post date:** [May 25, 2017, 7:56am UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080/1 "2017-05-25T07:56:57Z")

</div>

I wanted to know, is there any way I can configure x-pack with authorization only access. Means I should send the username only, and it will authenticate it according to the roles.

---

<div class="post-metadata">

**Author:** ![Buzzaes](https://avatars.discourse-cdn.com/v4/letter/b/5fc32e/32.png) [@Buzzaes](https://discuss.elastic.co/u/Buzzaes)\
**Post date:** [May 25, 2017, 10:57am UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080/2 "2017-05-25T10:57:37Z")

</div>

Something like this will do the trick:

curl -H "es-security-runas-user: borisTheBlade" -u es\_admin -XGET '[http://localhost:9200/](http://localhost:9200/)'

es\_admin is a user from the native realm, and borisTheBlade is a user from any realm you have configured.

This will use the native user to authenticate into the cluster, but will run the query as borisTheBlade (in theory). borisTheBlade will need their username configured into a role using the run\_as attribute (hint use a wild card).

Unfortunately there are 100 ways to skin this cat, but the ES documentation around this topic is absolute shit house.

---

<div class="post-metadata">

**Author:** ![him117](https://avatars.discourse-cdn.com/v4/letter/h/cab0a1/32.png) [@him117](https://discuss.elastic.co/u/him117)\
**Post date:** [May 25, 2017, 11:08am UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080/3 "2017-05-25T11:08:05Z")

</div>

Thanks for the reply.

Actually I want to do it through Active Directory group. The users username should be checked in that Active Directory list and should be able to query accordingly to the roles defined. I cannot pass the users password for the authentication (just authorisation).

---

<div class="post-metadata">

**Author:** ![Buzzaes](https://avatars.discourse-cdn.com/v4/letter/b/5fc32e/32.png) [@Buzzaes](https://discuss.elastic.co/u/Buzzaes)\
**Post date:** [May 25, 2017, 11:18am UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080/4 "2017-05-25T11:18:27Z")

</div>

I'm waiting on a response on using Active Directory in this way too - [Run\_as coupled with active directory auth](https://discuss.elastic.co/t/run-as-coupled-with-active-directory-auth/87068)

If it helps, I was able to use the LDAP realm to achieve exactly this, but not the AD realm - ES runs the query as the user I authenticate to Active Directory as, ad\_use. e.g.

curl -H "es-security-runas-user: borisTheBlade" -u ad\_user -XGET '[http://localhost:9200/](http://localhost:9200/)'

The ES logs indicate that the groups retrieved from AD are the those in which the ad\_user resides in, and not the borisTheBlade user.

And the reason why I need to use the AD realm anyway is because of a deeply nested AD group structure, which the LDAP realm does not support, as per the doc, but AD does.

---

<div class="post-metadata">

**Author:** ![him117](https://avatars.discourse-cdn.com/v4/letter/h/cab0a1/32.png) [@him117](https://discuss.elastic.co/u/him117)\
**Post date:** [May 30, 2017, 10:43am UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080/5 "2017-05-30T10:43:51Z")

</div>

No, runas feature is not working with AD group.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2017, 10:44am UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080/6 "2017-06-27T10:44:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
