# Elasticsearch Active Directory Authorization only support

**URL:** <https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080>\
**Category:** Elasticsearch\
**Created:** [May 25, 2017, 7:56am UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080 "2017-05-25T07:56:56Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Buzzaes](https://avatars.discourse-cdn.com/v4/letter/b/5fc32e/32.png) [@Buzzaes](https://discuss.elastic.co/u/Buzzaes)\
**Post date:** [May 25, 2017, 11:18am UTC](https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080/4 "2017-05-25T11:18:27Z")

</div>

I'm waiting on a response on using Active Directory in this way too - [Run\_as coupled with active directory auth](https://discuss.elastic.co/t/run-as-coupled-with-active-directory-auth/87068)

If it helps, I was able to use the LDAP realm to achieve exactly this, but not the AD realm - ES runs the query as the user I authenticate to Active Directory as, ad\_use. e.g.

curl -H "es-security-runas-user: borisTheBlade" -u ad\_user -XGET '[http://localhost:9200/](http://localhost:9200/)'

The ES logs indicate that the groups retrieved from AD are the those in which the ad\_user resides in, and not the borisTheBlade user.

And the reason why I need to use the AD realm anyway is because of a deeply nested AD group structure, which the LDAP realm does not support, as per the doc, but AD does.

---

_[View the full topic](https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080)._
