# How to add privileges to elastic/fleet-server

**URL:** <https://discuss.elastic.co/t/how-to-add-privileges-to-elastic-fleet-server/306153>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, fleet\
**Created:** [June 1, 2022, 5:20pm UTC](https://discuss.elastic.co/t/how-to-add-privileges-to-elastic-fleet-server/306153 "2022-06-01T17:20:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rupam1](https://avatars.discourse-cdn.com/v4/letter/r/48db29/32.png) [@rupam1](https://discuss.elastic.co/u/rupam1)\
**Post date:** [June 1, 2022, 5:20pm UTC](https://discuss.elastic.co/t/how-to-add-privileges-to-elastic-fleet-server/306153/1 "2022-06-01T17:20:22Z")

</div>

I have generated token with elastic fleet-server, while creating new index with that token I am getting security exception saying unauthorised user elastic/fleet-server

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 2, 2022, 1:33am UTC](https://discuss.elastic.co/t/how-to-add-privileges-to-elastic-fleet-server/306153/2 "2022-06-02T01:33:38Z")

</div>

You cannot grant additional access to that user. The `elastic/fleet-server` user exists solely to run fleet server, and has exactly the right access for that.

If you're trying to use it for something more, then you need to come up with a different approach.

---

<div class="post-metadata">

**Author:** ![rupam1](https://avatars.discourse-cdn.com/v4/letter/r/48db29/32.png) [@rupam1](https://discuss.elastic.co/u/rupam1)\
**Post date:** [June 2, 2022, 5:39am UTC](https://discuss.elastic.co/t/how-to-add-privileges-to-elastic-fleet-server/306153/3 "2022-06-02T05:39:12Z")

</div>

Hi thank you for the reply. So you mean token generated from elastic/fleet-server can not be used for index api right ? I mean to create index, search index etc so in such a case which token approach we should used ? Any idea ?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 2, 2022, 6:55am UTC](https://discuss.elastic.co/t/how-to-add-privileges-to-elastic-fleet-server/306153/4 "2022-06-02T06:55:46Z")

</div>

Why specifically do you want "token" authentication?

You can read about token based authentication methods here

- [Token-based authentication services | Elasticsearch Guide [8.2] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/token-authentication-services.html)

but, there's no magic in "tokens", you can achieve very similar outcomes using a username + password.

---

<div class="post-metadata">

**Author:** ![rupam1](https://avatars.discourse-cdn.com/v4/letter/r/48db29/32.png) [@rupam1](https://discuss.elastic.co/u/rupam1)\
**Post date:** [June 2, 2022, 11:08am UTC](https://discuss.elastic.co/t/how-to-add-privileges-to-elastic-fleet-server/306153/5 "2022-06-02T11:08:44Z")

</div>

Hi Thank you for the response. yes with user name and password we can access the index api and search the relevant details from the index.

However we are trying to secure the Elasticsearch index search api by passing the token as well in our application . while doing some more research in GitHub repository i could see that they have added more privileges for the fleet-server, so that code is available for the Elasticsearch license version ? correct me if i am assuming anything wrong ? completely new to Elasticsearch Thanks in advance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2022, 11:08am UTC](https://discuss.elastic.co/t/how-to-add-privileges-to-elastic-fleet-server/306153/6 "2022-06-30T11:08:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
