# New user created with API has admin role not recognized

**URL:** <https://discuss.elastic.co/t/new-user-created-with-api-has-admin-role-not-recognized/366551>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 13, 2024, 4:46pm UTC](https://discuss.elastic.co/t/new-user-created-with-api-has-admin-role-not-recognized/366551 "2024-09-13T16:46:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ismael\_mv](https://avatars.discourse-cdn.com/v4/letter/i/a9adbd/32.png) [@ismael\_mv](https://discuss.elastic.co/u/ismael_mv)\
**Post date:** [September 13, 2024, 4:46pm UTC](https://discuss.elastic.co/t/new-user-created-with-api-has-admin-role-not-recognized/366551/1 "2024-09-13T16:46:44Z")

</div>

Hi, I'm trying to create a user for Kibana (elastic is reserved so I can't use it).

I had executed these API call to do so, but admin role seems not beeing recognized. Do you have any clue ?  
(user and password are temporary, i'm trying to get this working, all my stack is on version 8.15.1)

```cmd
$ curl -s -X POST -u "elastic:myelasticpassword" -H "Content-Type: application/json" http://localhost:9200/_security/user/kibana_app -d '{"username":"kibana_app","password":"mykibanapassword","roles" : [admin]}'
{"created":true}%

$ curl -s -X GET -u "elastic:myelasticpassword" -H "Content-Type: application/json" http://localhost:9200/_security/user/kibana_app
{"kibana_app":{"username":"kibana_app","roles":["admin"],"full_name":null,"email":null,"metadata":{},"enabled":true}}%

$ curl -u kibana_app:mykibanapassword http://localhost:9200/_cluster/health
{"error":{"root_cause":[{"type":"security_exception","reason":"action [cluster:monitor/health] is unauthorized for user [kibana_app] with effective roles [] (assigned roles [admin] were not found), this action is granted by the cluster privileges [monitor,manage,all]"}],"type":"security_exception","reason":"action [cluster:monitor/health] is unauthorized for user [kibana_app] with effective roles [] (assigned roles [admin] were not found), this action is granted by the cluster privileges [monitor,manage,all]"},"status":403}%

```

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 16, 2024, 4:04am UTC](https://discuss.elastic.co/t/new-user-created-with-api-has-admin-role-not-recognized/366551/2 "2024-09-16T04:04:27Z")

</div>

> [@ismael\_mv](#):
>
> `(assigned roles [admin] were not found)`

It doesn't look like you have an `admin` role. Were you expecting one? Elasticsearch doesn't ship with one.

---

<div class="post-metadata">

**Author:** ![ismael\_mv](https://avatars.discourse-cdn.com/v4/letter/i/a9adbd/32.png) [@ismael\_mv](https://discuss.elastic.co/u/ismael_mv)\
**Post date:** [September 16, 2024, 7:09am UTC](https://discuss.elastic.co/t/new-user-created-with-api-has-admin-role-not-recognized/366551/3 "2024-09-16T07:09:58Z")

</div>

Hi TimV, I have had the user with admin role like exposed in the documentation. Here my JSON body of the first call :

```JSON
{
  "username":"kibana_app",
  "password":"mykibanapassword",
  "roles" : ["admin"]
}

```

The second call prove me that the user is created with the correct role.

The third one using this new created user is indicating that he can't find any role for him.

---

<div class="post-metadata">

**Author:** ![ismael\_mv](https://avatars.discourse-cdn.com/v4/letter/i/a9adbd/32.png) [@ismael\_mv](https://discuss.elastic.co/u/ismael_mv)\
**Post date:** [September 16, 2024, 7:16am UTC](https://discuss.elastic.co/t/new-user-created-with-api-has-admin-role-not-recognized/366551/4 "2024-09-16T07:16:32Z")

</div>

Oh I may have understand, Elasticsearch has no role named "admin", is that it ?

What are the default roles if there is no one named 'admin' ?

---

<div class="post-metadata">

**Author:** ![ismael\_mv](https://avatars.discourse-cdn.com/v4/letter/i/a9adbd/32.png) [@ismael\_mv](https://discuss.elastic.co/u/ismael_mv)\
**Post date:** [September 16, 2024, 9:44am UTC](https://discuss.elastic.co/t/new-user-created-with-api-has-admin-role-not-recognized/366551/5 "2024-09-16T09:44:48Z")

</div>

Thank you for your indication, I have had misunderstood at which level role was missing.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 16, 2024, 12:50pm UTC](https://discuss.elastic.co/t/new-user-created-with-api-has-admin-role-not-recognized/366551/6 "2024-09-16T12:50:26Z")

</div>

> [@ismael\_mv](#):
>
> What are the default roles if there is no one named 'admin' ?

The equivalent to admin would be the `superuser` role, this role has full access to everything in Elastic, so be careful in using it.

---

<div class="post-metadata">

**Author:** ![ismael\_mv](https://avatars.discourse-cdn.com/v4/letter/i/a9adbd/32.png) [@ismael\_mv](https://discuss.elastic.co/u/ismael_mv)\
**Post date:** [September 16, 2024, 1:16pm UTC](https://discuss.elastic.co/t/new-user-created-with-api-has-admin-role-not-recognized/366551/7 "2024-09-16T13:16:47Z")

</div>

Thank you Leandro, I will use this one carefully and learn how to create a new one.
