hi All,
I'm wondering if it is somehow possible to protect the internal (native) ES roles from being compromised by a "bad" AD admin, who could create an external (AD, LDAP) group "superuser" and add its own account to that group. As the result - full access to the ES cluster.
Again: supposed that an active_directory realm is configured with:
unmapped_groups_as_roles: true
Thanks!