# Host isolation permission issue

**URL:** https://discuss.elastic.co/t/host-isolation-permission-issue/350492
**Category:** Kibana
**Tags:** elastic-stack-security
**Created:** [January 5, 2024, 9:40pm UTC](https://discuss.elastic.co/t/host-isolation-permission-issue/350492 "2024-01-05T21:40:19Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![nmurilo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nmurilo/32/128244_2.png) [@nmurilo](https://discuss.elastic.co/u/nmurilo)
#### Post date: [January 5, 2024, 9:40pm UTC](https://discuss.elastic.co/t/host-isolation-permission-issue/350492/1 "2024-01-05T21:40:19Z")

</div>

I’m trying to grant host isolate perms configuring the "Role Mappings" but without success.  
Tried the same configuration steps (same rule) for regular Kibana users and it works like a charm.  
Have I missed something?

Thanks.

---

<div class="post-metadata">

### Author: ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)
#### Post date: [January 19, 2024, 9:01pm UTC](https://discuss.elastic.co/t/host-isolation-permission-issue/350492/2 "2024-01-19T21:01:17Z")

</div>

Hi, when you create a role mapping in the "Role Mappings" page, you select an existing role and add rules that assign roles to users. If you have an existing role that grants the Kibana application privilege to perform host isolation actions, you should select that role in the Role Mappings page.

1. It's not clear what you mean when you say use are using the "same rule" for "regular Kibana users." Does this mean that the privilege works when role mapping isn't involved?
2. Are you using [file-based role management](https://www.elastic.co/guide/en/elasticsearch/reference/current/defining-roles.html#roles-management-file), or has the role been created using the [API](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-get-role.html)? If you used the Kibana Stack Management pages to create the role, it has been created using the API.
3. Can you provide the JSON of the role declaration?

---

<div class="post-metadata">

### Author: ![nmurilo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nmurilo/32/128244_2.png) [@nmurilo](https://discuss.elastic.co/u/nmurilo)
#### Post date: [January 19, 2024, 9:37pm UTC](https://discuss.elastic.co/t/host-isolation-permission-issue/350492/3 "2024-01-19T21:37:30Z")

</div>

Hi Tim,  
thanks for reply.

_"If you have an existing role that grants the Kibana application privilege to perform host isolation actions, you should select that role in the Role Mappings page”_

Yes, I did it. I created a specific role called “host\_isolation” and “All” for:  
. Endpoint List, Trusted Applications, Host Isolation Exceptions, Blocklist, Event Filter, Elastic Defender Policy History and Host Isolation, in Security Section and None for everything else.

When I create an local user and use the same role it works. So I’m assuming the host\_isolation Role is correct and the issue is something related to Role Mapping itself.

I have to add I’m already using Role Mapping for others tasks with success.  
Any hits?  
Thanks Again

---

<div class="post-metadata">

### Author: ![Nikolaj\_Volgushev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolaj_volgushev/32/130399_2.png) [@Nikolaj\_Volgushev](https://discuss.elastic.co/u/Nikolaj_Volgushev)
#### Post date: [January 22, 2024, 9:47am UTC](https://discuss.elastic.co/t/host-isolation-permission-issue/350492/4 "2024-01-22T09:47:11Z")

</div>

Hi, a couple questions to narrow this down:

1. What exactly is not working? Given a user that's supposed to have the `host_isolation` role are you able to SSO into Kibana, but getting authorization errors when trying to execute host isolation related actions, or something else?
2. What stack version are you using?
3. Can you SSO into Kibana with a user that should get role mapped to `host_isolation` and call `GET /_security/authenticate` from Dev Tools? If you're okay with sharing these publicly, could you post the list of `roles` you get in the response? It's also fine to just confirm if `host_isolation` is among them or not. Also, it's worth looking at the user metadata; does it match what you would expect, based on your role mapping rules?
4. What realm is the user that is meant to get mapped to `host_isolation` authenticating with? There's additional logging we can enable to get more info, but it helps to know the authentication realm first.
5. As @tsullivan mentions, the role declaration (i.e., the output of `GET /_security/role/host_isolation`) and role mapping rule (`GET /_security/role_mapping/<mapping-name>`) would help, if you're willing to share them.

---

<div class="post-metadata">

### Author: ![nmurilo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nmurilo/32/128244_2.png) [@nmurilo](https://discuss.elastic.co/u/nmurilo)
#### Post date: [January 22, 2024, 3:36pm UTC](https://discuss.elastic.co/t/host-isolation-permission-issue/350492/5 "2024-01-22T15:36:19Z")

</div>

Hi Nikolaj,  
thanks for the replay.

1. "Not working" means works for local kibana users and not for SSO ones.

2. 8.11.4

3. I called GET .../authenticate and host\_isolation isn't showed up.  
That is the output sanitized[1]:

4. As I said others Role\_Mapping are already working well for SSO users (custom\_reporting i.e.) so, I'm assuming the authentication portion is ok.

5. Please find it in bellow [2] and [3] respectively the sanitized output.  
Also to compare, I'm sending [4] the custom\_reporting role (works with SSO).

Thanks again.

[1] - GET \_security/authenticate  
{  
"username": "5510487348",  
"roles": [  
"viewer",  
"editor"  
],  
"full\_name": "[user@domain.com](mailto:user@domain.com)",  
"email": "[user@domain.com](mailto:user@domain.com)",  
"metadata": {  
"saml\_email": [  
"[user@domain.com](mailto:user@domain.com)"  
],  
"saml\_nameid\_format": "urn:oasis:names:tc:SAML:2.0:nameid-format:transient",  
"saml(  
[http://saml.elastic-cloud.com/attributes/principal](http://saml.elastic-cloud.com/attributes/principal))":  
[  
"5510487348"  
],  
"saml\_roles": [  
"editor",  
"viewer"  
],  
"saml\_principal": [  
"5510487348"  
],  
"saml\_nameid": "\_56aed318267b78e185d34c0a5cca8f2507814f23",  
"saml(  
[http://saml.elastic-cloud.com/attributes/name](http://saml.elastic-cloud.com/attributes/name))":  
[  
"[user@domain.com](mailto:user@domain.com)"  
],  
"saml(  
[http://saml.elastic-cloud.com/attributes/email](http://saml.elastic-cloud.com/attributes/email))":  
[  
"[user@domain.com](mailto:user@domain.com)"  
],  
"saml(  
[http://saml.elastic-cloud.com/attributes/roles](http://saml.elastic-cloud.com/attributes/roles))":  
[  
"editor",  
"viewer"  
],  
"saml\_name": [  
"[user@ldomain.com](mailto:user@ldomain.com)"  
]  
},  
"enabled": true,  
"authentication\_realm": {  
"name": "cloud-saml-kibana",  
"type": "saml",  
"domain": "cloud-default"  
},  
"lookup\_realm": {  
"name": "cloud-saml-kibana",  
"type": "saml",  
"domain": "cloud-default"  
},  
"authentication\_type": "token"  
}

* * *

## [2] - GET \_security/role/host\_isolation { "host\_isolation": { "cluster": , "indices": [{ "names": [ ".items-_", ".lists-_", ".alerts-security.alerts-_", ".alerts-security.alerts-default,apm-_-transaction\*,auditbeat-_,endgame-_,filebeat-_,logs-_,packetbeat-_,traces-apm_,winlogbeat-_,-elastic-cloud-logs-", "metrics-_,metricbeat-_,.monitoring-_", "logs-network\_traffic._"], "privileges": ["read", "write", "view\_index\_metadata", "maintenance", "all"], "field\_security": { "grant": ["_"] }, "allow\_restricted\_indices": false } ], "applications": [{ "application": "kibana-.kibana", "privileges": [ "feature\_siem.minimal\_all", "feature\_siem.endpoint\_list\_all", "feature\_siem.trusted\_applications\_all", "feature\_siem.host\_isolation\_exceptions\_all", "feature\_siem.blocklist\_all", "feature\_siem.event\_filters\_all", "feature\_siem.policy\_management\_all", "feature\_siem.actions\_log\_management\_all", "feature\_siem.host\_isolation\_all"], "resources": ["\*"] } ], "run\_as": , "metadata": {}, "transient\_metadata": { "enabled": true } } }

[3] - GET \_security/role\_mapping/dom-map  
{  
"DOM-MAP": {  
"enabled": true,  
"roles": [  
"custom\_reporting",  
"host\_isolation"  
],  
"rules": {  
"all": [  
{  
"field": {  
"groups": "dc=domain,dc=com"  
}  
}  
]  
},  
"metadata": {}  
}  
}

* * *

[4] - GET \_security/role/custom\_reporting

{  
"custom\_reporting": {  
"cluster": ,  
"indices": [  
{  
"names": [  
"logs-_"  
],  
"privileges": [  
"read",  
"view\_index\_metadata",  
"all"  
],  
"field\_security": {  
"grant": [  
"_"  
],  
"except":   
},  
"allow\_restricted\_indices": false  
}  
],  
"applications": [  
{  
"application": "kibana-.kibana",  
"privileges": [  
"feature\_discover.all",  
"feature\_dashboard.all",  
"feature\_canvas.all",  
"feature\_maps.all",  
"feature\_ml.all",  
"feature\_graph.all",  
"feature\_visualize.all",  
"feature\_dev\_tools.all"  
],  
"resources": [  
"\*"  
]  
}  
],  
"run\_as": ,  
"metadata": {},  
"transient\_metadata": {  
"enabled": true  
}  
}  
}

---

<div class="post-metadata">

### Author: ![Nikolaj\_Volgushev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolaj_volgushev/32/130399_2.png) [@Nikolaj\_Volgushev](https://discuss.elastic.co/u/Nikolaj_Volgushev)
#### Post date: [January 23, 2024, 9:17am UTC](https://discuss.elastic.co/t/host-isolation-permission-issue/350492/6 "2024-01-23T09:17:10Z")

</div>

Thanks!

One request regarding the JSON payloads:

Could you edit your message to format those with the `</>` icon or pairs of triple backticks (```), and check the preview window to make sure it's properly formatted?

It's quite difficult to read otherwise.

Regarding the role mapping issue --

Based on the role-mapping definition you are mapping users based on:

```json
"field": {
  "groups": "dc=domain,dc=com"
}

```

However, in the authenticate response you posted I don't see any saml metadata fields that would match this. Could you check your SAML realm settings for [attribute mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/saml-guide-stack.html#saml-attributes-mapping), in particular that you have correctly configured `attributes.groups`? This field needs to point to a SAML attribute that contains the value you expect in the `field.groups` field of your role mapping definition. Note also that `"groups": "dc=domain,dc=com"` is a literal match, so if you have a SAML attribute like `"cn=users,dc=domain,dc=com"` the rule will not match.

One more useful debugging resource is our SAML trouble-shooting guide: [Common SAML issues | Elasticsearch Guide [8.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/trb-security-saml.html)

---

<div class="post-metadata">

### Author: ![nmurilo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nmurilo/32/128244_2.png) [@nmurilo](https://discuss.elastic.co/u/nmurilo)
#### Post date: [January 24, 2024, 2:33pm UTC](https://discuss.elastic.co/t/host-isolation-permission-issue/350492/7 "2024-01-24T14:33:39Z")

</div>

> [@Nikolaj\_Volgushev](#):
>
> Note also that `"groups": "dc=domain,dc=com"` is a literal match, so if you have a SAML attribute like `"cn=users,dc=domain,dc=com"` the rule will not match.

Hi Nikolai,

That role\_mapping already works for "custom\_reporting" role, so the SAML attributes are matching.  
I added a new role " host\_isolation" with:

```auto
"application": "kibana-.kibana",
"privileges": [
"feature_siem.minimal_all",
"feature_siem.endpoint_list_all",
"feature_siem.trusted_applications_all",
"feature_siem.host_isolation_exceptions_all",
"feature_siem.blocklist_all",
"feature_siem.event_filters_all",
"feature_siem.policy_management_all",
"feature_siem.actions_log_management_all",
"feature_siem.host_isolation_all"

```

And it doesn't work.

Thanks again.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 21, 2024, 2:34pm UTC](https://discuss.elastic.co/t/host-isolation-permission-issue/350492/8 "2024-02-21T14:34:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
