# Minimum privileges for all spaces

**URL:** <https://discuss.elastic.co/t/minimum-privileges-for-all-spaces/192317>\
**Category:** Kibana\
**Created:** [July 25, 2019, 8:18pm UTC](https://discuss.elastic.co/t/minimum-privileges-for-all-spaces/192317 "2019-07-25T20:18:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![AQ\_Amra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aq_amra/32/42976_2.png) [@AQ\_Amra](https://discuss.elastic.co/u/AQ_Amra)\
**Post date:** [July 25, 2019, 8:18pm UTC](https://discuss.elastic.co/t/minimum-privileges-for-all-spaces/192317/1 "2019-07-25T20:18:09Z")

</div>

Hi,

I am trying to create a setup with multiple spaces, where a user should be restricted to a single space.

I have created a second space, however when i set the role to only have read access for dashboards to this space, when i login with that user i see the default space as a selectable space.

I am using Kibana 7.2.0

In Kibana 6.7.2 there used to be a feature called "Minimum privileges for all spaces" which resolved the above (in the role config) has this moved elsewhere?

The user is assigned the role above + Kibana\_dashboard\_only\_user

Attached role privileges ![Screenshot%20from%202019-07-25%2022-15-19](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0ed7d9c89c5c67d43555247b37f76bb33d3c7717.png)

 ![Screenshot%20from%202019-07-25%2022-14-55](https://us1.discourse-cdn.com/elastic/original/3X/2/c/2c740a6448da5af2a76b31a14a07814e5b97344c.png) and view of spaces from the user login.

Many thanks in advance.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [July 26, 2019, 7:55pm UTC](https://discuss.elastic.co/t/minimum-privileges-for-all-spaces/192317/2 "2019-07-26T19:55:09Z")

</div>

Hey @AQ_Amra, the `kibana_dashboard_only_user` grants the user read-only access to every Space in Kibana, if you only wish for them to have access to the single space you'll want to remove that role.

Dashboard Only Mode is effectively deprecated with the introduction of feature level privileges, so I'd highly recommend no longer using the `kibana_dashboard_only_user` role any longer and only using custom roles to grant access to a single dashboard.

---

<div class="post-metadata">

**Author:** ![AQ\_Amra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aq_amra/32/42976_2.png) [@AQ\_Amra](https://discuss.elastic.co/u/AQ_Amra)\
**Post date:** [July 29, 2019, 8:33am UTC](https://discuss.elastic.co/t/minimum-privileges-for-all-spaces/192317/3 "2019-07-29T08:33:29Z")

</div>

Hi Brandon,

Many thanks for your response, much appreciated.

So i have removed the

> kibana\_dashboard\_only\_user

From the user privileges, and now it only has access to the space that i required.

However the settings option in kibana now appears (although they wont have access to any of the items). Is there a way to remove the settings options?

I have tried setting the new role as a Dashboards only roles in Kibana \> advanced settings

 ![Screenshot%20from%202019-07-29%2010-30-55](https://us1.discourse-cdn.com/elastic/original/3X/0/b/0b3829e0425f77113b679ed205e6eefa3bff84ae.png)

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [July 29, 2019, 2:57pm UTC](https://discuss.elastic.co/t/minimum-privileges-for-all-spaces/192317/4 "2019-07-29T14:57:38Z")

</div>

@AQ_Amra, this isn't currently possible. You'll notice that even though the "Management" application is visible, the user won't be authorized to use any of those management sections. We're tracking the effort to completely hide the management application here: [https://github.com/elastic/kibana/issues/35965](https://github.com/elastic/kibana/issues/35965)

---

<div class="post-metadata">

**Author:** ![AQ\_Amra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aq_amra/32/42976_2.png) [@AQ\_Amra](https://discuss.elastic.co/u/AQ_Amra)\
**Post date:** [July 29, 2019, 3:09pm UTC](https://discuss.elastic.co/t/minimum-privileges-for-all-spaces/192317/5 "2019-07-29T15:09:49Z")

</div>

Great, thanks for the update.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 26, 2019, 3:10pm UTC](https://discuss.elastic.co/t/minimum-privileges-for-all-spaces/192317/6 "2019-08-26T15:10:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
