# Kibana handle multiple authentication methods

**URL:** <https://discuss.elastic.co/t/kibana-handle-multiple-authentication-methods/265202>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [February 23, 2021, 12:54pm UTC](https://discuss.elastic.co/t/kibana-handle-multiple-authentication-methods/265202 "2021-02-23T12:54:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![anon42972578](https://avatars.discourse-cdn.com/v4/letter/a/da6949/32.png) [@anon42972578](https://discuss.elastic.co/u/anon42972578)\
**Post date:** [February 23, 2021, 12:54pm UTC](https://discuss.elastic.co/t/kibana-handle-multiple-authentication-methods/265202/1 "2021-02-23T12:54:37Z")

</div>

Hello,

we have some questions about how to handle multiple authentication methods in Kibana. It would be great if we can learn from you and your solutions or your ideas.

at the moment we can offer three different authentication methods:

- native
- saml
- oidc

there is an interesting UI selector where users can select which authentication method they want to use.

- is it possible to use this UI selector only when the prefered (highest order setting) failed ?
- or can we configure the UI selector behind a different endpoint ?

Also there is the "/login" option for using native authentication.

- is it possible to configure more URL endpoints for our realms?  
example: [my-kibana-url.com/saml1](http://my-kibana-url.com/saml1)

Or do you have other solutions how to handle our requirements ?

- native authentication via /login for administrators --\> check
- oidc realm for all users (default setting)
- saml as fallback if oidc is not working

best regards

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [February 23, 2021, 1:07pm UTC](https://discuss.elastic.co/t/kibana-handle-multiple-authentication-methods/265202/2 "2021-02-23T13:07:53Z")

</div>

Hi,

> [@anon42972578](#):
>
> is it possible to use this UI selector only when the prefered (highest order setting) failed ?

I think this is done by Kibana if you configure e.g. native and activeDirectory(password will be checked against native and then against AD). But native, saml and oidc are totally different so I guess that will not work.

> [@anon42972578](#):
>
> is it possible to configure more URL endpoints for my realms?

I have not found the documentation link for it - only the reference for anonymous access [here](https://www.elastic.co/guide/en/kibana/current/embedding.html#_authentication) but you should be able to call Kibana like this: `https://localhost:5601/app/monitoring?auth_provider_hint=saml1` which should try to use the Saml provider.

> [@anon42972578](#):
>
> Or do you have other solutions how to handle our requirements ?

I think you should also be able to install two separate Kibana installations:

- one has native authentication and has a very restricted firewall because only the admins should be able to access this
- one has oidc and saml configured

Be aware that some settings have to be the same across all kibana instances: [Use Kibana in a production environment | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/production.html#load-balancing-kibana)

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [March 12, 2021, 5:33am UTC](https://discuss.elastic.co/t/kibana-handle-multiple-authentication-methods/265202/5 "2021-03-12T05:33:54Z")

</div>

Hi,

Unfortunately, I am not experienced with nginx as we explicitly **want** to have different Kibana Urls so the firewall ensures the admin interface is secure.

I am sure there are users here that are able to help you with this question far better than myself 🙂

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2021, 7:45am UTC](https://discuss.elastic.co/t/kibana-handle-multiple-authentication-methods/265202/7 "2021-04-19T07:45:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
