# Loose output permissions given to Elastic Agent

**URL:** <https://discuss.elastic.co/t/loose-output-permissions-given-to-elastic-agent/292297>\
**Category:** Beats\
**Tags:** elastic-stack-security, fleet, elastic-agent\
**Created:** [December 17, 2021, 11:38am UTC](https://discuss.elastic.co/t/loose-output-permissions-given-to-elastic-agent/292297 "2021-12-17T11:38:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DamianoChini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/damianochini/32/99207_2.png) [@DamianoChini](https://discuss.elastic.co/u/DamianoChini)\
**Post date:** [December 17, 2021, 11:38am UTC](https://discuss.elastic.co/t/loose-output-permissions-given-to-elastic-agent/292297/1 "2021-12-17T11:38:25Z")

</div>

Hi all!  
If in Fleet I configure a Policy without any integration, the Elastic Agents associated with that Policy receive output permissions on `logs-*`, `metrics-*`, `traces-*` and `synthetics-*`.  
This means that these Elastic Agents will be able to write on namespaces which are not their namespaces, compromising the security in terms of separation of the namespaces.  
If I use namespaces to separate the tenancy of the data, I expect that removing all integrations from a policy will not allow the tenant of the agent to write data into the datastreams of other tenants.

In particular by inspecting the Elastic Agent with no integration configured, we can see that a "\_fallback" permission is added, which allows to write on all namespaces.

```auto
output_permissions:
  default:
    _elastic_agent_checks:
      cluster:
      - monitor
    _elastic_agent_monitoring:
      indices:
      - names:
        - logs-elastic_agent.apm_server-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - metrics-elastic_agent.apm_server-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - logs-elastic_agent.auditbeat-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - metrics-elastic_agent.auditbeat-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - logs-elastic_agent-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - metrics-elastic_agent.elastic_agent-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - metrics-elastic_agent.endpoint_security-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - logs-elastic_agent.endpoint_security-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - logs-elastic_agent.filebeat-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - metrics-elastic_agent.filebeat-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - logs-elastic_agent.fleet_server-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - metrics-elastic_agent.fleet_server-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - logs-elastic_agent.heartbeat-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - metrics-elastic_agent.heartbeat-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - logs-elastic_agent.metricbeat-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - metrics-elastic_agent.metricbeat-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - logs-elastic_agent.osquerybeat-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - metrics-elastic_agent.osquerybeat-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - logs-elastic_agent.packetbeat-default
        privileges:
        - auto_configure
        - create_doc
      - names:
        - metrics-elastic_agent.packetbeat-default
        privileges:
        - auto_configure
        - create_doc
    _fallback:
      cluster:
      - monitor
      indices:
      - names:
        - logs-*
        - metrics-*
        - traces-*
        - synthetics-*
        - .logs-endpoint.diagnostic.collection-*
        privileges:
        - auto_configure
        - create_doc

```

---

<div class="post-metadata">

**Author:** ![nchaulet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nchaulet/32/77896_2.png) [@nchaulet](https://discuss.elastic.co/u/nchaulet)\
**Post date:** [December 17, 2021, 1:39pm UTC](https://discuss.elastic.co/t/loose-output-permissions-given-to-elastic-agent/292297/2 "2021-12-17T13:39:49Z")

</div>

Hi @DamianoChini thanks for reporting that issue.

Unfortunately this \_fallback permissions is currently the expected behavior when an agent policy does not have any integrations.  
We are working on fixing this by removing this concept of default permissions [[Fleet] Reduce DEFAULT\_PERMISSIONS · Issue #119562 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/119562)  
In the mean time I really encourage you to add an integration to mitigate that issue.

---

<div class="post-metadata">

**Author:** ![DamianoChini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/damianochini/32/99207_2.png) [@DamianoChini](https://discuss.elastic.co/u/DamianoChini)\
**Post date:** [December 17, 2021, 2:39pm UTC](https://discuss.elastic.co/t/loose-output-permissions-given-to-elastic-agent/292297/3 "2021-12-17T14:39:44Z")

</div>

Ok good! I didn't find the open github issue previously,  
thank you for the reply!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2022, 4:40pm UTC](https://discuss.elastic.co/t/loose-output-permissions-given-to-elastic-agent/292297/4 "2022-01-14T16:40:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
