# Role has manage\_index\_templates, but getting error "action \[indices:admin/mappings/get\] is unauthorized for user"

**URL:** <https://discuss.elastic.co/t/role-has-manage-index-templates-but-getting-error-action-indices-admin-mappings-get-is-unauthorized-for-user/118391>\
**Category:** Elasticsearch\
**Created:** [February 5, 2018, 6:43am UTC](https://discuss.elastic.co/t/role-has-manage-index-templates-but-getting-error-action-indices-admin-mappings-get-is-unauthorized-for-user/118391 "2018-02-05T06:43:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Suny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suny/32/22082_2.png) [@Suny](https://discuss.elastic.co/u/Suny)\
**Post date:** [February 5, 2018, 6:43am UTC](https://discuss.elastic.co/t/role-has-manage-index-templates-but-getting-error-action-indices-admin-mappings-get-is-unauthorized-for-user/118391/1 "2018-02-05T06:43:20Z")

</div>

Hi. I'm creating a second Kibana on hosted elasticsearch (cloud.elastic.co). The second kibana role has "all" privilege on her .kibana\_2 index, and cluster privileges "monitor" and "manage\_index\_templates". Still, she gets the error message: `[security_exception] action [indices:admin/mappings/get] is unauthorized for user [kibana_2]`. I have to give her "all" on ".kibana" to work. But this is precisely what I wanted to avoid. The reason for creating the second kibana was to hide all the experimental indices and dashboards that I'm creating in the first kibana.  
This looks like a bug to me, like kibana in some (initial?) action is querying the standard .kibana index instead of the one that is configured.  
Kibana Version: 6.1.3

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [February 9, 2018, 11:46pm UTC](https://discuss.elastic.co/t/role-has-manage-index-templates-but-getting-error-action-indices-admin-mappings-get-is-unauthorized-for-user/118391/2 "2018-02-09T23:46:58Z")

</div>

Hi Suny, the `.kibana` index is where Kibana stores all of the settings and things it needs to run. So all users will need some level of access to this index to use Kibana. Have you tried giving the user the additional role of `kibana_user`? This will grant the minimum privileges required for any user of Kibana. For more information you can take a look at the [built-in roles docs](https://www.elastic.co/guide/en/x-pack/current/built-in-roles.html).

Thanks,  
CJ

---

<div class="post-metadata">

**Author:** ![Suny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suny/32/22082_2.png) [@Suny](https://discuss.elastic.co/u/Suny)\
**Post date:** [February 12, 2018, 8:42pm UTC](https://discuss.elastic.co/t/role-has-manage-index-templates-but-getting-error-action-indices-admin-mappings-get-is-unauthorized-for-user/118391/3 "2018-02-12T20:42:46Z")

</div>

Hi CJ. I thought the index where Kibana stores it's stuff was configurable in kibana.yml, [https://www.elastic.co/guide/en/kibana/current/settings.html](https://www.elastic.co/guide/en/kibana/current/settings.html) , kibana.index.  
And yes, I compared the privileges with those of kibana\_user. The only difference was "all" on .kibana. Which I gave to the second kibana, as explained above.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2018, 8:42pm UTC](https://discuss.elastic.co/t/role-has-manage-index-templates-but-getting-error-action-indices-admin-mappings-get-is-unauthorized-for-user/118391/4 "2018-03-12T20:42:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
