# Role 'reporting\_user' is deprecated. Please use Kibana feature privileges instead

**URL:** <https://discuss.elastic.co/t/role-reporting-user-is-deprecated-please-use-kibana-feature-privileges-instead/294593>\
**Category:** Kibana\
**Created:** [January 17, 2022, 2:01pm UTC](https://discuss.elastic.co/t/role-reporting-user-is-deprecated-please-use-kibana-feature-privileges-instead/294593 "2022-01-17T14:01:58Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![jsteenkamp](https://avatars.discourse-cdn.com/v4/letter/j/58956e/32.png) [@jsteenkamp](https://discuss.elastic.co/u/jsteenkamp)\
**Post date:** [January 17, 2022, 2:01pm UTC](https://discuss.elastic.co/t/role-reporting-user-is-deprecated-please-use-kibana-feature-privileges-instead/294593/1 "2022-01-17T14:01:58Z")

</div>

latest version 7.16.3 (forever free edition)

management \> users

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/9/697d48834ee6696c234997492f1cf9c89d4ee906.png)

> **[Kibana privileges | Kibana Guide \[7.17\] | Elastic](https://www.elastic.co/guide/en/kibana/current/kibana-privileges.html)**
>
> Kibana provides you with several options to share \*Discover\* saved searches, dashboards, \*Visualize Library\* visualizations, and \*Canvas\* workpads with others, or on a website.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/8/a80270cf9ffcbc65fa40d8c3aa25f4458b4fd239.png)

How do I grant users reporting permissions without using the deprecated reporting\_user in the forever free edition that does not support sub-feature privileges?

---

<div class="post-metadata">

**Author:** ![tomx1](https://avatars.discourse-cdn.com/v4/letter/t/779978/32.png) [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Post date:** [February 9, 2022, 2:53pm UTC](https://discuss.elastic.co/t/role-reporting-user-is-deprecated-please-use-kibana-feature-privileges-instead/294593/2 "2022-02-09T14:53:56Z")

</div>

Same question here... if I understand correctly, then they have made it a payable feature 😔

---

<div class="post-metadata">

**Author:** ![jsteenkamp](https://avatars.discourse-cdn.com/v4/letter/j/58956e/32.png) [@jsteenkamp](https://discuss.elastic.co/u/jsteenkamp)\
**Post date:** [February 10, 2022, 12:10pm UTC](https://discuss.elastic.co/t/role-reporting-user-is-deprecated-please-use-kibana-feature-privileges-instead/294593/3 "2022-02-10T12:10:08Z")

</div>

I have looked at [https://github.com/elastic/kibana/pull/94966](https://github.com/elastic/kibana/pull/94966) and also tried to include `xpack.reporting.roles.enabled: false` in the `kibana.yml` file. So far, without luck.

@tsullivan how does this relate to the forever free basic edition of the stack?

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [February 10, 2022, 4:29pm UTC](https://discuss.elastic.co/t/role-reporting-user-is-deprecated-please-use-kibana-feature-privileges-instead/294593/4 "2022-02-10T16:29:32Z")

</div>

Hi, the Basic Elastic license provides some, but not all, security features. One thing it does not provide is the ability to define a custom role that grants access Kibana Application features.

_If you are on a Basic license, using the deprecated role is necessary to generate CSV reports, which are another Basic license feature._  
**EDIT BY JOE:** this isn't true, see comment below.

Sorry about the confusion. I would welcome a writeup on an issue at [https://github.com/elastic/kibana/issues/new](https://github.com/elastic/kibana/issues/new)

---

<div class="post-metadata">

**Author:** ![jportner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jportner/32/75692_2.png) [@jportner](https://discuss.elastic.co/u/jportner)\
**Post date:** [February 10, 2022, 6:37pm UTC](https://discuss.elastic.co/t/role-reporting-user-is-deprecated-please-use-kibana-feature-privileges-instead/294593/5 "2022-02-10T18:37:28Z")

</div>

> [@tomx1](#):
>
> Same question here... if I understand correctly, then they have made it a payable feature 😔

> [@jsteenkamp](#):
>
> @tsullivan how does this relate to the forever free basic edition of the stack?

Security team member here!

@tomx1 @jsteenkamp sorry for the confusion, I think we need to improve our documentation and our role management UI.

Downloading CSV reports (from Discover or Dashboard) has always been part of the Basic license, and that isn't changing. When you use the new Reporting authorization (when you have configured `xpack.reporting.roles.enabled: false`), that means access to Reporting is now controlled by Kibana feature privileges instead of the separate `reporting_user` role.

To clarify: all you need to create CSV reports with Kibana feature privileges is to have "All" access to the Discover and/or Dashboard feature.

Sub-feature privileges, which are available with a Gold+ license, allow you to customize that level of access. For example, you may want to give users who have "Read" access the _additional_ ability to create CSV reports. Or, you may want to _prevent_ users with "All" access from creating CSV reports. With a Gold+ license, you just have more granular control.

The role management UI changes were originally geared more towards subscription users, but now that we have more sub-features that are available with the Basic license I think it makes sense to enhance that UI to show administrators exactly what users can access with a given feature. I opened an issue for the latter here: [#125289](https://github.com/elastic/kibana/issues/125289)

Hope that helps!

---

<div class="post-metadata">

**Author:** ![jsteenkamp](https://avatars.discourse-cdn.com/v4/letter/j/58956e/32.png) [@jsteenkamp](https://discuss.elastic.co/u/jsteenkamp)\
**Post date:** [February 10, 2022, 7:07pm UTC](https://discuss.elastic.co/t/role-reporting-user-is-deprecated-please-use-kibana-feature-privileges-instead/294593/6 "2022-02-10T19:07:51Z")

</div>

thank you! @jportner

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [February 11, 2022, 5:27pm UTC](https://discuss.elastic.co/t/role-reporting-user-is-deprecated-please-use-kibana-feature-privileges-instead/294593/7 "2022-02-11T17:27:42Z")

</div>

Thanks a ton for the clarification, @jportner

---

<div class="post-metadata">

**Author:** ![stuwee](https://avatars.discourse-cdn.com/v4/letter/s/919ad9/32.png) [@stuwee](https://discuss.elastic.co/u/stuwee)\
**Post date:** [March 11, 2022, 2:37pm UTC](https://discuss.elastic.co/t/role-reporting-user-is-deprecated-please-use-kibana-feature-privileges-instead/294593/8 "2022-03-11T14:37:22Z")

</div>

Cleared it up for me! Thank you!

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [March 22, 2022, 8:38pm UTC](https://discuss.elastic.co/t/role-reporting-user-is-deprecated-please-use-kibana-feature-privileges-instead/294593/9 "2022-03-22T20:38:19Z")

</div>

I have added a section to our documentation to explain setting up user access for CSV reports, with a free basic license: [Configure reporting in Kibana | Kibana Guide [7.16] | Elastic](https://www.elastic.co/guide/en/kibana/7.16/secure-reporting.html#grant-user-access-basic)

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [March 22, 2022, 8:38pm UTC](https://discuss.elastic.co/t/role-reporting-user-is-deprecated-please-use-kibana-feature-privileges-instead/294593/10 "2022-03-22T20:38:28Z")

</div>


