# Kibana\_dashboard\_only\_user and Spaces Security issue

**URL:** <https://discuss.elastic.co/t/kibana-dashboard-only-user-and-spaces-security-issue/158684>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [November 29, 2018, 5:46am UTC](https://discuss.elastic.co/t/kibana-dashboard-only-user-and-spaces-security-issue/158684 "2018-11-29T05:46:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dallas\_Toth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dallas_toth/32/22630_2.png) [@Dallas\_Toth](https://discuss.elastic.co/u/Dallas_Toth)\
**Post date:** [November 29, 2018, 5:46am UTC](https://discuss.elastic.co/t/kibana-dashboard-only-user-and-spaces-security-issue/158684/1 "2018-11-29T05:46:05Z")

</div>

Kibana 6.5.1 in Elastic Cloud

When you have a User with \> kibana\_dashboard\_only\_user and a Role  
That user has access to all spaces even though the Role only has read on one space.

My role has a indies and Privileges read and one space set as read.

I tested this by removing the Kibana\_dashboard\_only\_user and then my user only had access to the one Space.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [November 29, 2018, 6:57am UTC](https://discuss.elastic.co/t/kibana-dashboard-only-user-and-spaces-security-issue/158684/2 "2018-11-29T06:57:28Z")

</div>

This is to be expected.  
Much like the `kibana_user` role, the built-in `kibana_dashboard_only_user` role has access to all spaces.  
If you wish to secure individual spaces [you should not use these roles](https://www.elastic.co/guide/en/kibana/6.5/xpack-security-authorization.html#_spaces).

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 29, 2018, 7:02am UTC](https://discuss.elastic.co/t/kibana-dashboard-only-user-and-spaces-security-issue/158684/3 "2018-11-29T07:02:10Z")

</div>

I believe there its an [open issue](https://github.com/elastic/kibana/issues/25701) around this and that we are working on improving documentation.

---

<div class="post-metadata">

**Author:** ![Dallas\_Toth](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dallas_toth/32/22630_2.png) [@Dallas\_Toth](https://discuss.elastic.co/u/Dallas_Toth)\
**Post date:** [November 29, 2018, 3:24pm UTC](https://discuss.elastic.co/t/kibana-dashboard-only-user-and-spaces-security-issue/158684/4 "2018-11-29T15:24:51Z")

</div>

Yeppers.  
[https://github.com/elastic/kibana/issues/25701](https://github.com/elastic/kibana/issues/25701) the walk through in here by using the Advanced Settings Dashboard \> Dashboards only roles worked perfectly.  
Thx this saved me from needing to spin up Kibana outside of Elastic Cloud.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2018, 3:24pm UTC](https://discuss.elastic.co/t/kibana-dashboard-only-user-and-spaces-security-issue/158684/5 "2018-12-27T15:24:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
