# Setting privileges to spaces, privileges not working on default space

**URL:** <https://discuss.elastic.co/t/setting-privileges-to-spaces-privileges-not-working-on-default-space/187977>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [June 28, 2019, 6:28am UTC](https://discuss.elastic.co/t/setting-privileges-to-spaces-privileges-not-working-on-default-space/187977 "2019-06-28T06:28:09Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saurabh\_Sharma\_IIT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saurabh_sharma_iit/32/48921_2.png) [@Saurabh\_Sharma\_IIT](https://discuss.elastic.co/u/Saurabh_Sharma_IIT)\
**Post date:** [June 28, 2019, 6:28am UTC](https://discuss.elastic.co/t/setting-privileges-to-spaces-privileges-not-working-on-default-space/187977/1 "2019-06-28T06:28:09Z")

</div>

Hi, I am using security feature in my project. I have three spaces, test1, test2 and default. I created a role and set privileges:  
test1: read  
test2: none  
default: none

Now I created a user: test\_user with this role and when I login with this, I cannot acces test2, good but I can access default. That is wrong.

I want test\_user to access only test1 and no other space.  
How to do that.  
I am new to elastic and any help how I can solve this issue.

Thank you  
Saurabh

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [June 28, 2019, 7:59am UTC](https://discuss.elastic.co/t/setting-privileges-to-spaces-privileges-not-working-on-default-space/187977/2 "2019-06-28T07:59:13Z")

</div>

Hi,

I have the same and it works for me. Which version of Kibana do you have? Do you have " Minimum privileges for all spaces" set to none in the Role configuration?

BR  
Wolfram

UPDATE: You can try executing GET \_xpack/security/\_authenticate in the Dev Tools console. This gives you all roles the user has -maybe the access to the default space comes from another role?

---

<div class="post-metadata">

**Author:** ![Saurabh\_Sharma\_IIT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saurabh_sharma_iit/32/48921_2.png) [@Saurabh\_Sharma\_IIT](https://discuss.elastic.co/u/Saurabh_Sharma_IIT)\
**Post date:** [June 28, 2019, 8:04am UTC](https://discuss.elastic.co/t/setting-privileges-to-spaces-privileges-not-working-on-default-space/187977/3 "2019-06-28T08:04:43Z")

</div>

Hi Wolfram, thanks for your response.

Version: 7.1

" Minimum privileges for all spaces" is set to "none"

---

<div class="post-metadata">

**Author:** ![Saurabh\_Sharma\_IIT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saurabh_sharma_iit/32/48921_2.png) [@Saurabh\_Sharma\_IIT](https://discuss.elastic.co/u/Saurabh_Sharma_IIT)\
**Post date:** [June 28, 2019, 8:11am UTC](https://discuss.elastic.co/t/setting-privileges-to-spaces-privileges-not-working-on-default-space/187977/4 "2019-06-28T08:11:14Z")

</div>

In "Higher privileges for individual spaces", I have selected the space which I want user to view and set privilege to "read". rest I have not set anything i.e. in elasticsearch section I have set nothing.

I though that might be default space is by default available to all the user and it can not be hide from users. But as you mention that this works for you, I couldn't find what I am doing wrong.

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [June 28, 2019, 8:35am UTC](https://discuss.elastic.co/t/setting-privileges-to-spaces-privileges-not-working-on-default-space/187977/5 "2019-06-28T08:35:59Z")

</div>

> [@Wolfram\_Haussig](#):
>
> UPDATE: You can try executing GET \_xpack/security/\_authenticate in the Dev Tools console. This gives you all roles the user has -maybe the access to the default space comes from another role?

Have you tried that?

---

<div class="post-metadata">

**Author:** ![Saurabh\_Sharma\_IIT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saurabh_sharma_iit/32/48921_2.png) [@Saurabh\_Sharma\_IIT](https://discuss.elastic.co/u/Saurabh_Sharma_IIT)\
**Post date:** [June 28, 2019, 8:45am UTC](https://discuss.elastic.co/t/setting-privileges-to-spaces-privileges-not-working-on-default-space/187977/6 "2019-06-28T08:45:05Z")

</div>

Yes, it gives only one role, which I created and in that role I have set read only to only one space rest are set to none.

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [June 28, 2019, 8:46am UTC](https://discuss.elastic.co/t/setting-privileges-to-spaces-privileges-not-working-on-default-space/187977/7 "2019-06-28T08:46:21Z")

</div>

I use Version 6.5.4 so maybe another one using your version can replicate this.

---

<div class="post-metadata">

**Author:** ![Saurabh\_Sharma\_IIT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saurabh_sharma_iit/32/48921_2.png) [@Saurabh\_Sharma\_IIT](https://discuss.elastic.co/u/Saurabh_Sharma_IIT)\
**Post date:** [June 28, 2019, 8:53am UTC](https://discuss.elastic.co/t/setting-privileges-to-spaces-privileges-not-working-on-default-space/187977/8 "2019-06-28T08:53:41Z")

</div>

Are you using paid one. I mean I am trying the security features which are made free with the open source/basic one. I guess those security features are there in version 6.8 and 7 and not in 6.5

link to blog:

> **[Secure Elasticsearch with TLS encryption and role-based access control](https://www.elastic.co/blog/getting-started-with-elasticsearch-security)**
>
> Secure your Elasticsearch clusters -- and the other components of the Elastic Stack -- with node-to-node TLS and role-based access control (RBAC). These features and more are now available free with the default distribution of Elasticsearch and...

Thanks for help 😄

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [June 28, 2019, 9:49am UTC](https://discuss.elastic.co/t/setting-privileges-to-spaces-privileges-not-working-on-default-space/187977/9 "2019-06-28T09:49:23Z")

</div>

Yes, you are right: the security features for the basic license are available in 6.8/7.1 and later only but we have a gold license for that reason.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2019, 9:49am UTC](https://discuss.elastic.co/t/setting-privileges-to-spaces-privileges-not-working-on-default-space/187977/10 "2019-07-26T09:49:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
