# Integrated Windows Authentication support?

**URL:** <https://discuss.elastic.co/t/integrated-windows-authentication-support/82331>\
**Category:** Elasticsearch\
**Created:** [April 13, 2017, 4:28pm UTC](https://discuss.elastic.co/t/integrated-windows-authentication-support/82331 "2017-04-13T16:28:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![data.dev](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@data.dev](https://discuss.elastic.co/u/data.dev)\
**Post date:** [April 13, 2017, 4:28pm UTC](https://discuss.elastic.co/t/integrated-windows-authentication-support/82331/1 "2017-04-13T16:28:22Z")

</div>

Hello,  
My client is planning to run Elasticsearch on Windows servers which users will accessed from Windows machines (server and desktop), all part of an Active Directory domain.

I understand that XPack allows users to authenticate against Active Directory, but one thing I am not clear from the documentation is how users actually pass their credentials to Elasticserver.

Do they need to pass their Windows credentials in each request (e.g. from basic auth headers), or is there a way to use Integrated Windows Authentication (i.e. Kerberos) so that the users' existing logged in identity can be used, without passing credentials to Elasticserver?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [April 13, 2017, 4:37pm UTC](https://discuss.elastic.co/t/integrated-windows-authentication-support/82331/2 "2017-04-13T16:37:52Z")

</div>

We currently use a LDAP connection to active directory so user's need to pass their credentials with the requests to authenticate. Kerberos is a feature that we have on our roadmap; however it is possible to implement Kerberos support in a custom realm extension.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2017, 4:49pm UTC](https://discuss.elastic.co/t/integrated-windows-authentication-support/82331/3 "2017-05-11T16:49:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
