# How to Configure X-Pack for Active Directory

**URL:** <https://discuss.elastic.co/t/how-to-configure-x-pack-for-active-directory/73193>\
**Category:** Elasticsearch\
**Created:** [January 30, 2017, 11:04am UTC](https://discuss.elastic.co/t/how-to-configure-x-pack-for-active-directory/73193 "2017-01-30T11:04:58Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![arianayay](https://avatars.discourse-cdn.com/v4/letter/a/f4b2a3/32.png) [@arianayay](https://discuss.elastic.co/u/arianayay)\
**Post date:** [January 30, 2017, 11:04am UTC](https://discuss.elastic.co/t/how-to-configure-x-pack-for-active-directory/73193/1 "2017-01-30T11:04:58Z")

</div>

Hi All,

I'm having a problem configuring Active Directory in X-pack for elasticsearch and kibana. May I know if there is a video tutorial or detailed steps for this? Currently, I have this setup.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1fc11017493451437a919ff64a383928b5db0fc6.png)

but this is the error I received if I want to connect to my elasticsearch.  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/f/fd26989ae4af51aaa7f82038783a0c780f79d945.png)

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [January 30, 2017, 11:44am UTC](https://discuss.elastic.co/t/how-to-configure-x-pack-for-active-directory/73193/2 "2017-01-30T11:44:03Z")

</div>

Please use code snippets (the `</>` icon) instead of image attachments.

Are you trying to authenticate for many domains or a single one? The username in the error message has a NetBIOS domain name appended to the front. If using multiple domains you will need to connect to the global catalog port. [https://www.elastic.co/guide/en/x-pack/current/active-directory-realm.html#\_multiple\_domain\_support](https://www.elastic.co/guide/en/x-pack/current/active-directory-realm.html#_multiple_domain_support)

---

<div class="post-metadata">

**Author:** ![arianayay](https://avatars.discourse-cdn.com/v4/letter/a/f4b2a3/32.png) [@arianayay](https://discuss.elastic.co/u/arianayay)\
**Post date:** [January 31, 2017, 1:15am UTC](https://discuss.elastic.co/t/how-to-configure-x-pack-for-active-directory/73193/3 "2017-01-31T01:15:22Z")

</div>

Hi,

I'm only trying to connect to a single domain. How does URL work and how can I access the URL? Is the role\_mapping I've provided correct? Should I also set the role.yml? Also, I cannot access the elasticsearch pretty using the account I provided in the role\_mapping.yml. Should I create a separate folder for elastic in the Active Directory or can I use an existing one? if yes, how do you configure AD since I've tried the steps in the elastic site but it is not working. Maybe I've missed some details.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [January 31, 2017, 1:45pm UTC](https://discuss.elastic.co/t/how-to-configure-x-pack-for-active-directory/73193/4 "2017-01-31T13:45:37Z")

</div>

Did you use the proper values for your domain instead of `domain.com`? If so did you try logging in with just `SQLENG.User2`?

This blog may help some [https://www.elastic.co/blog/quick-start-guide-configuring-elasticsearch-with-shield-and-active-directory](https://www.elastic.co/blog/quick-start-guide-configuring-elasticsearch-with-shield-and-active-directory)

---

<div class="post-metadata">

**Author:** ![arianayay](https://avatars.discourse-cdn.com/v4/letter/a/f4b2a3/32.png) [@arianayay](https://discuss.elastic.co/u/arianayay)\
**Post date:** [February 3, 2017, 3:28am UTC](https://discuss.elastic.co/t/how-to-configure-x-pack-for-active-directory/73193/5 "2017-02-03T03:28:39Z")

</div>

Hi,

Yes, I have configured the correct domain name. Should I also edit the role.yml of X-Pack? Is ingest node needed in the configuration?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 3, 2017, 5:28am UTC](https://discuss.elastic.co/t/how-to-configure-x-pack-for-active-directory/73193/6 "2017-02-03T05:28:47Z")

</div>

It's hard for us to provide you with detailed information - we don't know the details for your Active Directory server, nor the exact configuration that you've used for your elasticsearch realm (since you've chosen to hide some of the private information).

The _general_ advice that I can give is:

- You should trying logging in as `SQLENG.User2` (_without_ the `DS\\` domain prefix)

- The URL should point to your Active Directory server. There are a number of LDAP tools that you can use to test whether you have configured the correct URL. If you do not have access to any such tools, you might want to check with your AD administrators, or you can search for something like _ldap search tools {your-operating-system}_.

- X-Pack security makes a clear distinction between _authentication_ (validating the username/password, etc) and _authorization_ (roles, permissions, etc). The error message: `unable to authenticate user ...` implies that the problem is with authenticating the user against your AD server, and is not a problem with your roles and mapping. We cannot tell whether your role mapping is correct until the authentication problem is solved.

- You will find more detailed error messages in the elasticsearch logs. By default this log is `logs/elasticsearch.log` but it may be in a different location depending on how you installed and configured your node. These logs will help with working out whether X-Pack Security is able to successfully connect to your AD server.

- You can increase the level of logging by [turning on debug logging](https://www.elastic.co/guide/en/elasticsearch/reference/current/misc-cluster.html#cluster-logger) for `logger.org.elasticsearch.xpack.security.authc`

---

<div class="post-metadata">

**Author:** ![arianayay](https://avatars.discourse-cdn.com/v4/letter/a/f4b2a3/32.png) [@arianayay](https://discuss.elastic.co/u/arianayay)\
**Post date:** [February 3, 2017, 7:34am UTC](https://discuss.elastic.co/t/how-to-configure-x-pack-for-active-directory/73193/8 "2017-02-03T07:34:56Z")

</div>

Hi,

I have this configuration in my elasticsearch.yml

xpack:  
security:  
authc:  
realms:  
active\_directory:  
type: active\_directory  
order: 0  
domain\_name: [ds.dev.com](http://ds.dev.com)  
url: ldaps://CTL16SP1W12R2AS.ds.dev.com:389  
unmapped\_groups\_as\_roles: false

native1:  
type: native  
order: 1  
while for roles\_mapping.yml

admin:

- "CN=sqleng.user2,OU=SQL,OU=Lab,OU=CIO Segment Servers,DC=ds,DC=dev,DC=com"

Now elasticsearch is not running and not generating a log file.

Sorry but I am new with X-pack configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2017, 7:35am UTC](https://discuss.elastic.co/t/how-to-configure-x-pack-for-active-directory/73193/9 "2017-03-03T07:35:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
