# How to get authorized with sAMAcount

**URL:** <https://discuss.elastic.co/t/how-to-get-authorized-with-samacount/67337>\
**Category:** Elasticsearch\
**Created:** [November 28, 2016, 11:37am UTC](https://discuss.elastic.co/t/how-to-get-authorized-with-samacount/67337 "2016-11-28T11:37:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gilisade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gilisade/32/98740_2.png) [@gilisade](https://discuss.elastic.co/u/gilisade)\
**Post date:** [November 28, 2016, 11:37am UTC](https://discuss.elastic.co/t/how-to-get-authorized-with-samacount/67337/1 "2016-11-28T11:37:26Z")

</div>

Hi  
i'm trying to use x-pack - shield  
i've set up an active directory realm in my ES server  
then i mapped a domain user to a superuser role  
when i try to log in to the kibana with that domain user everything seems to work fine  
i am able to log in  
BUT  
nothing is showing ,the kibana logo is there and the side bar menu also but everything else is blank - when i press the tabs nothing happens  
then i realized that the user is authenticated but does not get permissions (even though it is mapped to a role)  
the CN of our users is in hebrew (and the sAMAcount is in english) and since the authentication part is using the sAMAcount everything is working fine in that part  
but the role mapping part is using the CN which is in hebrew like i mentioned

is there any way to map a user to a role with something else than the CN - it just doesn't support hebrew

---

<div class="post-metadata">

**Author:** ![gilisade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gilisade/32/98740_2.png) [@gilisade](https://discuss.elastic.co/u/gilisade)\
**Post date:** [November 30, 2016, 8:34am UTC](https://discuss.elastic.co/t/how-to-get-authorized-with-samacount/67337/2 "2016-11-30T08:34:59Z")

</div>

HI an UPDATE  
i could not resolve this specific problem  
but what i did is to create a security group in AD - named in an english name  
add the user to this group  
and map the GROUP to the role - then it worked just fine

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [December 1, 2016, 10:00pm UTC](https://discuss.elastic.co/t/how-to-get-authorized-with-samacount/67337/3 "2016-12-01T22:00:23Z")

</div>

Hi there, thank you for posting the solution to your problem!

CJ

---

<div class="post-metadata">

**Author:** ![gilisade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gilisade/32/98740_2.png) [@gilisade](https://discuss.elastic.co/u/gilisade)\
**Post date:** [December 4, 2016, 5:31am UTC](https://discuss.elastic.co/t/how-to-get-authorized-with-samacount/67337/4 "2016-12-04T05:31:08Z")

</div>

No problem 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 1, 2017, 5:31am UTC](https://discuss.elastic.co/t/how-to-get-authorized-with-samacount/67337/5 "2017-01-01T05:31:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
