# Shield and Azure AD?

**URL:** <https://discuss.elastic.co/t/shield-and-azure-ad/654>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 14, 2015, 12:02am UTC](https://discuss.elastic.co/t/shield-and-azure-ad/654 "2015-05-14T00:02:41Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![bradleach](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bradleach/32/44853_2.png) [@bradleach](https://discuss.elastic.co/u/bradleach)\
**Post date:** [May 14, 2015, 12:02am UTC](https://discuss.elastic.co/t/shield-and-azure-ad/654/1 "2015-05-14T00:02:41Z")

</div>

Does anyone know if it is possible to use Azure AD with Shield?

I'd love to have it set up so that you could manage users in Azure AD and secure Kibana via Shield.

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [May 14, 2015, 2:44am UTC](https://discuss.elastic.co/t/shield-and-azure-ad/654/2 "2015-05-14T02:44:23Z")

</div>

We don't currently support Azure AD - it uses a different API than regular AD or LDAP. It is something that we are considering on our longer term roadmap, but isn't planned for our next release.

If Azure AD adds an LDAP interface, it should be easy to support it with the existing Shield realms.

In the mean time, would it be possible to use the native esusers authentication realm to protect ES and Kibana?

---

<div class="post-metadata">

**Author:** ![bradleach](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bradleach/32/44853_2.png) [@bradleach](https://discuss.elastic.co/u/bradleach)\
**Post date:** [May 14, 2015, 3:23am UTC](https://discuss.elastic.co/t/shield-and-azure-ad/654/3 "2015-05-14T03:23:30Z")

</div>

Thanks for the info! Native esusers will be fine for now. 🙂

---

<div class="post-metadata">

**Author:** ![andreasv](https://avatars.discourse-cdn.com/v4/letter/a/57b2e6/32.png) [@andreasv](https://discuss.elastic.co/u/andreasv)\
**Post date:** [September 14, 2016, 3:29pm UTC](https://discuss.elastic.co/t/shield-and-azure-ad/654/4 "2016-09-14T15:29:15Z")

</div>

Shouldn't it be possible to customize this by implementing your own realm that authenticates against Azure API's?

[https://www.elastic.co/guide/en/shield/current/custom-realms.html](https://www.elastic.co/guide/en/shield/current/custom-realms.html)

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [September 14, 2016, 4:18pm UTC](https://discuss.elastic.co/t/shield-and-azure-ad/654/5 "2016-09-14T16:18:30Z")

</div>

Yes, absolutely! You could definitely build a custom realm that connects to the Azure AD APIs.

In addition to the docs you link to, we also have an example realm that we provide for reference:

> **[elastic/shield-custom-realm-example](https://github.com/elastic/shield-custom-realm-example)**
>
> Contribute to shield-custom-realm-example development by creating an account on GitHub.

and there are various community-created realms (we don't support these as we didn't build them, but they do serve as useful examples) , like this one:

> **[codecentric/elasticsearch-shield-kerberos-realm](https://github.com/codecentric/elasticsearch-shield-kerberos-realm)**
>
> elasticsearch-shield-kerberos-realm - Kerberos/SPNEGO custom realm for Elasticsearch Shield 2.0

---

<div class="post-metadata">

**Author:** ![aliostad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aliostad/32/4046_2.png) [@aliostad](https://discuss.elastic.co/u/aliostad)\
**Post date:** [December 9, 2016, 10:59am UTC](https://discuss.elastic.co/t/shield-and-azure-ad/654/6 "2016-12-09T10:59:58Z")

</div>

Hi,

Are there any plans to add this support? Also would you accept PR or you would prefer these to be independent community projects?

Thanks  
Ali

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [December 12, 2016, 1:33am UTC](https://discuss.elastic.co/t/shield-and-azure-ad/654/7 "2016-12-12T01:33:35Z")

</div>

Hi Brad,

We have a number of other realms (think SAML, Kerberos) that are more widely deployed at our customers. However, that said, we encourage you to build a custom realm and open source it. We maintain an [open source example realm](https://github.com/elastic/shield-custom-realm-example), which should serve as a good example to get you started.

There is also a[Kerberos realm](https://github.com/codecentric/elasticsearch-shield-kerberos-realm) that was produced by one of our partners - we don't build or support it, but it's a good example of a complex Shield realm in oss.

Thanks,  
Steve

---

<div class="post-metadata">

**Author:** ![aliostad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aliostad/32/4046_2.png) [@aliostad](https://discuss.elastic.co/u/aliostad)\
**Post date:** [December 15, 2016, 9:29am UTC](https://discuss.elastic.co/t/shield-and-azure-ad/654/8 "2016-12-15T09:29:17Z")

</div>

Thanks.

But Azure AD works with OAuth2/OpenID Connect... is this supported in Elasticsearch?  
This would obviously trigger a redirect to the login page instead of accepting username/password.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:41pm UTC](https://discuss.elastic.co/t/shield-and-azure-ad/654/9 "2017-07-06T13:41:22Z")

</div>


