# RBAC - Manage spaces - how to disable it?

**URL:** <https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [June 16, 2026, 11:41am UTC](https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881 "2026-06-16T11:41:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ts\_P](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ts_p/32/147683_2.png) [@Ts\_P](https://discuss.elastic.co/u/Ts_P)\
**Post date:** [June 16, 2026, 11:41am UTC](https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881/1 "2026-06-16T11:41:05Z")

</div>

In elastic stack 9.4 we want to disable /enable "Manage spaces" functionality.  
I found only this in the documentation:  
"An example of a built-in role is kibana\_admin. Assigning this role to your users will grant access to all of Kibana's features. This includes the ability to manage spaces."

Is there another way to enable that functionality? I don't want to give users such a role.

I saw that by default this functionality is hidden.

```auto
   "applications": [
      {
        "application": "kibana-.kibana",
        "privileges": [
          "feature_discover_v2.all",
          "feature_dashboard_v2.all",
          "feature_visualize_v2.all",
          "feature_indexPatterns.all",
          "feature_savedObjectsManagement.all",
          "feature_fleetv2.read",
          "feature_fleet.read"
        ],
        "resources": [
          "*"
        ]
      }
    ]

```

---

<div class="post-metadata">

**Author:** ![covj12](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/covj12/32/147474_2.png) [@covj12](https://discuss.elastic.co/u/covj12)\
**Post date:** [June 30, 2026, 12:34am UTC](https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881/2 "2026-06-30T00:34:11Z")

</div>

You can create a custom role that excludes the spaces feature privilege.

Use the following API call to create the role

```json
PUT /api/security/role/my_custom_role
{
  "elasticsearch": {
    "cluster": [],
    "indices": []
  },
  "kibana": [
    {
      "base": [],
      "feature": {
        "discover_v2": ["all"],
        "dashboard_v2": ["all"],
        "visualize_v2": ["all"],
        "indexPatterns": ["all"],
        "savedObjectsManagement": ["all"],
        "fleetv2": ["read"],
        "fleet": ["read"]
        # No "spaces" entry → Manage spaces access denied
      },
      "spaces": ["*"]
    }
  ]
}

```

Once the role is created, assign it to the relevant users via Stack Management → Security → Users, or using the Kibana user management API.

---

<div class="post-metadata">

**Author:** ![Ts\_P](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ts_p/32/147683_2.png) [@Ts\_P](https://discuss.elastic.co/u/Ts_P)\
**Post date:** [June 30, 2026, 6:12pm UTC](https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881/3 "2026-06-30T18:12:31Z")

</div>

I will test it and let you know

---

<div class="post-metadata">

**Author:** ![covj12](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/covj12/32/147474_2.png) [@covj12](https://discuss.elastic.co/u/covj12)\
**Post date:** [July 1, 2026, 4:16am UTC](https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881/4 "2026-07-01T04:16:08Z")

</div>

> [@Ts\_P](#):
>
> Manage spaces

Ah, wrong API endpoint, try this instead

```auto
PUT _security/role/my_custom_role
{
  "cluster": [],
  "indices": [],
  "applications": [
    {
      "application": "kibana-.kibana",
      "privileges": [
        "feature_discover_v2.all",
        "feature_dashboard_v2.all",
        "feature_visualize_v2.all",
        "feature_indexPatterns.all",
        "feature_savedObjectsManagement.all",
        "feature_fleetv2.read",
        "feature_fleet.read"
      ],
      "resources": ["*"]
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![Ts\_P](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ts_p/32/147683_2.png) [@Ts\_P](https://discuss.elastic.co/u/Ts_P)\
**Post date:** [July 1, 2026, 3:42pm UTC](https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881/5 "2026-07-01T15:42:30Z")

</div>

Hi , thanks a lot . This unfortunately does not solve our issue. It is hidden by default . I want to find which one is the option to enable it for specific users (without set kibana\_admin role to their users)

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [July 2, 2026, 4:48am UTC](https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881/6 "2026-07-02T04:48:02Z")

</div>

Hello @Ts_P

Related to this concern i already see below github issues which are open :

> <https://github.com/elastic/kibana/issues/51759>
>
> Currently, the ability to manage spaces is only granted with the "All" base priv…ileges, and must be granted at all spaces. This isn't obvious, and it also is limiting because you can't create a role which can only manage spaces or manage a subset of spaces.

> <https://github.com/elastic/kibana/issues/226026>
>
> \*\*Summary:\*\*  
> Currently, managing spaces in Kibana requires the \`kibana\_admin\` …role, which grants broad administrative privileges that many customers consider too powerful for this specific task. To better support least-privilege access models, we request the introduction of a dedicated, granular privilege that allows users to create and manage spaces without granting full admin rights.
> 
> \*\*Background:\*\*  
> Customers have expressed a need for finer-grained control over space management permissions. Kibana currently checks for space management capabilities via an internal capabilities API, but there is no way to enable this capability independently of the full \`kibana\_admin\` role. This limits flexibility and forces customers to grant excessive privileges to users responsible only for space-related tasks.
> 
> \*\*Proposal:\*\*  
> \- Introduce a new, specific “Manage Spaces” privilege that can be assigned independently of \`kibana\_admin\`.
> \- Update the capabilities API to recognize and enforce this new privilege.
> \- Reflect the new privilege in Kibana RBAC/UI for easy assignment and management.

Thanks!!

---

<div class="post-metadata">

**Author:** ![Ts\_P](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ts_p/32/147683_2.png) [@Ts\_P](https://discuss.elastic.co/u/Ts_P)\
**Post date:** [July 2, 2026, 7:26am UTC](https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881/7 "2026-07-02T07:26:56Z")

</div>

thanks a lot for clarifying @Tortoise . thanks @covj12 for your help as well
