# OpenId with google let all user to be connected

**URL:** <https://discuss.elastic.co/t/openid-with-google-let-all-user-to-be-connected/206217>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [November 1, 2019, 10:00pm UTC](https://discuss.elastic.co/t/openid-with-google-let-all-user-to-be-connected/206217 "2019-11-01T22:00:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![anasoid](https://avatars.discourse-cdn.com/v4/letter/a/94ad74/32.png) [@anasoid](https://discuss.elastic.co/u/anasoid)\
**Post date:** [November 1, 2019, 10:00pm UTC](https://discuss.elastic.co/t/openid-with-google-let-all-user-to-be-connected/206217/1 "2019-11-01T22:00:08Z")

</div>

I have configure ELastic cloud with OpenId using google succesfly and i can logged in with my email.'  
My problem is every gmail account can be logged in

There is any way to restrict only access to chosed users and manage their roles.

In google documentation we have obligation to check our database.

[https://developers.google.com/identity/protocols/OpenIDConnect#authuser](https://developers.google.com/identity/protocols/OpenIDConnect#authuser)  
After obtaining user information from the ID token, you should query your app's user database.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 12, 2019, 7:10am UTC](https://discuss.elastic.co/t/openid-with-google-let-all-user-to-be-connected/206217/2 "2019-11-12T07:10:32Z")

</div>

> [@anasoid](#):
>
> My problem is every gmail account can be logged in

Just a clarification for future readers, that this means "every user in your Gmail tenant" and not every gmail user

> [@anasoid](#):
>
> There is any way to restrict only access to chosed users and manage their roles.

I would argue that this is something that needs to be restricted on the authenticating side , i.e. the OpenID Provider, which is Google in your case. If google doesn't offer that feature/functionality, then what you can do on the Elastic Stack side is to create role mappings that only assign the necessary roles to specific groups of users. Then all the others ( that are not intended to log in ) will get no roles and as such will get a `403` from Kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 10, 2019, 7:10am UTC](https://discuss.elastic.co/t/openid-with-google-let-all-user-to-be-connected/206217/3 "2019-12-10T07:10:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
