# Kibana + Elasticsearch add active directory

**URL:** <https://discuss.elastic.co/t/kibana-elasticsearch-add-active-directory/304834>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [May 16, 2022, 2:31pm UTC](https://discuss.elastic.co/t/kibana-elasticsearch-add-active-directory/304834 "2022-05-16T14:31:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dmitrymig](https://avatars.discourse-cdn.com/v4/letter/d/6a8cbe/32.png) [@Dmitrymig](https://discuss.elastic.co/u/Dmitrymig)\
**Post date:** [May 16, 2022, 2:31pm UTC](https://discuss.elastic.co/t/kibana-elasticsearch-add-active-directory/304834/1 "2022-05-16T14:31:16Z")

</div>

hello guys, I've been trying to set up authorization for a domain controller for a very long time and everything has failed, I've read a lot of topics and can't find an answer, help me)  
telnet domain:389 successful

logger.org.Elasticsearch.discovery: DEBUG  
xpack.security.enabled: true  
xpack:  
security:  
authc:  
realms:  
ldap:  
ldap1:  
order: 0  
url: "ldap://10.102.5.101:389"  
bind\_dn: "cn=s-kibana,ou=Users,ou=MCREDIT,dc=mgc,dc=local"  
bind\_password: 123qweASD  
user\_search:  
base\_dn: "dc=mgc,dc=local"  
filter: "(cn={0})"  
group\_search:  
base\_dn: "dc=mgc,dc=local"  
files:  
role\_mapping: "/etc/Elasticsearch/role\_mappings.yml"  
unmapped\_groups\_as\_roles: false

My file, also for roles file

superuser:

- cn=kibana-users,cn=Groups,cn=DC,dc=mgc,dc=local
- cn=DDenisov-adm,cn=Admins-Accounts,cn=Users,cn=MIGCREDIT,dc=mgc,dc=local  
user:
- "cn=kibana-users,cn=Groups,cn=DC,dc=mgc,dc=local"

I'm trying to log in as a user who is in kibana-users and under my DDenisov-adm account, but I get an error 403  
I don't see errors in the Elasticsearch log, I also turned on the debug, but it didn't help to see the errors  
I logged in to kibana under the Elasticsearch user and there are no errors in the role-mapping, I don’t know what to do anymore) please help

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 17, 2022, 12:30am UTC](https://discuss.elastic.co/t/kibana-elasticsearch-add-active-directory/304834/2 "2022-05-17T00:30:11Z")

</div>

Hit the [Authenticate API](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-authenticate.html) as a user from your LDAP realm.

The response to that API should give you hints about where the problem might be.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2022, 12:30am UTC](https://discuss.elastic.co/t/kibana-elasticsearch-add-active-directory/304834/3 "2022-06-14T00:30:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
