# How to edit role descriptor for a service account

**URL:** <https://discuss.elastic.co/t/how-to-edit-role-descriptor-for-a-service-account/316379>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [October 11, 2022, 8:05pm UTC](https://discuss.elastic.co/t/how-to-edit-role-descriptor-for-a-service-account/316379 "2022-10-11T20:05:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![CarlosD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlosd/32/107752_2.png) [@CarlosD](https://discuss.elastic.co/u/CarlosD)\
**Post date:** [October 11, 2022, 8:05pm UTC](https://discuss.elastic.co/t/how-to-edit-role-descriptor-for-a-service-account/316379/1 "2022-10-11T20:05:10Z")

</div>

I would like to edit the default role descriptor for [service account](https://www.elastic.co/guide/en/elasticsearch/reference/current/service-accounts.html) elastic/kibana, however, I do not find a way to achieve this.  
Alternatively, I created a [role](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-put-role.html) with the privileges I want to have on service account elastic/kibana, but I do not find the way to assign this role to the existing elastic/kibana.  
Any help will be appreciated.  
Thanks!

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 14, 2022, 12:18am UTC](https://discuss.elastic.co/t/how-to-edit-role-descriptor-for-a-service-account/316379/2 "2022-10-14T00:18:31Z")

</div>

No it's not possible and that's by design. I am not sure why you want to do that. Service accounts are designed to be used by specific services, e.g. Kibana and therefore their privileges are precisely scoped for the service. Adding or removing privileges from it can risk either breaking the services or security vulnerability. If you need to do something that is not allowed for the `elastic/kibana` service account, it is better off to create an entirely separate user.

---

<div class="post-metadata">

**Author:** ![CarlosD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlosd/32/107752_2.png) [@CarlosD](https://discuss.elastic.co/u/CarlosD)\
**Post date:** [October 14, 2022, 1:00pm UTC](https://discuss.elastic.co/t/how-to-edit-role-descriptor-for-a-service-account/316379/3 "2022-10-14T13:00:33Z")

</div>

Hi @Yang_Wang , thanks for checking this issue.  
Ok, yes I was getting the following in the logs of an application:

```auto
ERROR security_exception: [security_exception] Reason: action [indices:admin/settings/update] is unauthorized for user [elastic/kibana] on indices [index-name-here], this action is granted by the index privileges [manage,all]

```

I thought that I could add the privileges to these indices to the elastic/kibana service account

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 17, 2022, 4:28am UTC](https://discuss.elastic.co/t/how-to-edit-role-descriptor-for-a-service-account/316379/4 "2022-10-17T04:28:25Z")

</div>

In what context did you get the error? Is this for something configured out of the box by some Elastic product? In that case, I'd consider this a bug and appreciate if you could provide reproduction steps. Or did you configure something on your own? Thanks!

---

<div class="post-metadata">

**Author:** ![CarlosD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlosd/32/107752_2.png) [@CarlosD](https://discuss.elastic.co/u/CarlosD)\
**Post date:** [October 17, 2022, 2:20pm UTC](https://discuss.elastic.co/t/how-to-edit-role-descriptor-for-a-service-account/316379/5 "2022-10-17T14:20:38Z")

</div>

Hi @Yang_Wang ,

> In what context did you get the error?

This is an application I installed and configured on top of Elastic Stack, so I do not think it is a bug, it is not an Elastic product.  
As there is no workaround (or shouldn't be) to provide service account elastic/kibana with permissions over other indices I will do some more testing.  
Thanks a lot!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2022, 2:21pm UTC](https://discuss.elastic.co/t/how-to-edit-role-descriptor-for-a-service-account/316379/6 "2022-11-14T14:21:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
