# Mapping Users and Groups to Roles "other" realms

**URL:** <https://discuss.elastic.co/t/mapping-users-and-groups-to-roles-other-realms/87528>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Created:** [May 30, 2017, 8:57am UTC](https://discuss.elastic.co/t/mapping-users-and-groups-to-roles-other-realms/87528 "2017-05-30T08:57:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Niklas](https://avatars.discourse-cdn.com/v4/letter/n/34f0e0/32.png) [@Niklas](https://discuss.elastic.co/u/Niklas)\
**Post date:** [May 30, 2017, 8:57am UTC](https://discuss.elastic.co/t/mapping-users-and-groups-to-roles-other-realms/87528/1 "2017-05-30T08:57:23Z")

</div>

For native or file it is possible to map users to roles via the API or Kibana.  
But role mappings for Active Directory realms e.g. you need to create a role\_mapping.yml file.  
I suppose I can just can create it in /mnt/data/elastic/[ip]/services/allocator/containers/elasticsearch/[id]/instance-0000000001/config/x-pack/ but then it will be lost when I am doing changes/upgrades and a new container is created  
How do I solve that in Cloud Enterprise?

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [June 1, 2017, 3:47pm UTC](https://discuss.elastic.co/t/mapping-users-and-groups-to-roles-other-realms/87528/2 "2017-06-01T15:47:08Z")

</div>

Hi @Niklas

AD is definitely not well supported in ECE at the moment, it is on our "todo" list. The main issue is the additional files like `role_mapping.yaml`, as you already deduced.

While it's likely that it could be gotten to work reliably via [user bundles](https://www.elastic.co/guide/en/cloud-enterprise/current/ElasticsearchUserBundle.html) together with a [custom location for the role mapping file](https://www.elastic.co/guide/en/shield/shield-1.1/active_directory.html#ad-role-mapping), we are not treating it as officially supported at the moment.

It is something that will be coming soon with official support though!

Alex

---

<div class="post-metadata">

**Author:** ![Niklas](https://avatars.discourse-cdn.com/v4/letter/n/34f0e0/32.png) [@Niklas](https://discuss.elastic.co/u/Niklas)\
**Post date:** [June 2, 2017, 5:59am UTC](https://discuss.elastic.co/t/mapping-users-and-groups-to-roles-other-realms/87528/3 "2017-06-02T05:59:22Z")

</div>

Thanks. I'll try that.. might also come in handy for other files.  
I have solved it by setting the unmapped\_groups\_as\_roles to yes and created roles that have the same name as the AD-groups and the same privileges as the predefined ones.  
I just think it is neater to use the predefined roles and map them to AD-groups but this will do.

I also noticed that you are not allowed to add xpack security realms to the elasticsearch.yml for logging-and-metrics in the 1.0 version.. it worked in the beta.

---

<div class="post-metadata">

**Author:** ![JohnnyB](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnnyb/32/13450_2.png) [@JohnnyB](https://discuss.elastic.co/u/JohnnyB)\
**Post date:** [June 2, 2017, 9:47am UTC](https://discuss.elastic.co/t/mapping-users-and-groups-to-roles-other-realms/87528/4 "2017-06-02T09:47:42Z")

</div>

Hi @Alex,

FYI,  
I'm interesting for AD support and role\_mapping.yaml management by ECE as well since we are using this in our actuel clusters.

Best,  
Johnny

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2017, 9:48am UTC](https://discuss.elastic.co/t/mapping-users-and-groups-to-roles-other-realms/87528/5 "2017-06-16T09:48:11Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
