# Restrict Settings panel to authorized users

**URL:** <https://discuss.elastic.co/t/restrict-settings-panel-to-authorized-users/36549>\
**Category:** Kibana\
**Created:** [December 7, 2015, 3:34pm UTC](https://discuss.elastic.co/t/restrict-settings-panel-to-authorized-users/36549 "2015-12-07T15:34:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nick\_Vecellio](https://avatars.discourse-cdn.com/v4/letter/n/aca169/32.png) [@Nick\_Vecellio](https://discuss.elastic.co/u/Nick_Vecellio)\
**Post date:** [December 7, 2015, 3:34pm UTC](https://discuss.elastic.co/t/restrict-settings-panel-to-authorized-users/36549/1 "2015-12-07T15:34:19Z")

</div>

Hello!

We're currently working on upgrading our elasticsearch cluster to kibana4, and something we would like to do is restrict most users from accessing the 'settings' panel. We've attempted to do this through nginx unsuccessfully, as the settings panel is not populated by a second request (so restricting location becomes impossible).

Is this possible without the use of Shield?

Thanks!

---

<div class="post-metadata">

**Author:** ![Nick\_Vecellio](https://avatars.discourse-cdn.com/v4/letter/n/aca169/32.png) [@Nick\_Vecellio](https://discuss.elastic.co/u/Nick_Vecellio)\
**Post date:** [December 7, 2015, 4:39pm UTC](https://discuss.elastic.co/t/restrict-settings-panel-to-authorized-users/36549/2 "2015-12-07T16:39:11Z")

</div>

I was able to get this sorted, for anyone who is interested. Since it seems that kibana loads everything at once, including the settings - having authentication for settings at the nginx level doesn't really work.

That said, individual POST requests are sent for settings changes, so you CAN require auth for post requests.

To do so (or, regex to match the path to \_update)-

location ~ ^/elasticsearch/.kibana/config/4.1.3/\_update$ {  
limit\_except GET {  
auth\_basic "Restricted";  
auth\_basic\_user\_file /path/to/passwd/file;  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 8, 2015, 3:46am UTC](https://discuss.elastic.co/t/restrict-settings-panel-to-authorized-users/36549/3 "2015-12-08T03:46:21Z")

</div>

We're working on releasing this sort of functionality into KB as well, though I don't have a timeframe.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:07pm UTC](https://discuss.elastic.co/t/restrict-settings-panel-to-authorized-users/36549/4 "2017-07-06T14:07:19Z")

</div>


