# Shield drawback, Please correct me if I am wrong

**URL:** https://discuss.elastic.co/t/shield-drawback-please-correct-me-if-i-am-wrong/25282
**Category:** Elasticsearch
**Tags:** elastic-stack-security
**Created:** [July 10, 2015, 5:53am UTC](https://discuss.elastic.co/t/shield-drawback-please-correct-me-if-i-am-wrong/25282 "2015-07-10T05:53:52Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)
#### Post date: [July 10, 2015, 5:53am UTC](https://discuss.elastic.co/t/shield-drawback-please-correct-me-if-i-am-wrong/25282/1 "2015-07-10T05:53:53Z")

</div>

Hi Shield Experts

I have created 2 users , **admin** and **abc** and assign roles to these users . **Admin** can access all the indices , but user **abc** can oly access one index . Now admin user has created dashboard which has many vizulizations from different indices .

## **Problem**

Since **abc** user ir restricted to only one index , so he won't be able to see the data in the dashboard created by **admin**. But **abc** can see the code behind and dashboard plus he can see name of the dashboard or some other stuff too. I am aware why this is happening because both the users have read access to **.kiaban** index which stores all the visualizations and dashboards .

## Question

Can we design or assign separate .kibana index as per customer/user . With this approach I can restrict user completely .So my goal is **abc** user should not see the dashboard created by **admin**.

Thanks  
VG

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [July 10, 2015, 7:12am UTC](https://discuss.elastic.co/t/shield-drawback-please-correct-me-if-i-am-wrong/25282/2 "2015-07-10T07:12:49Z")

</div>

You can specify the name of the index Kibana uses in the kibana.yml file. If you create two separate Kibana instances, on different URL/ports, you can have different Kibana indices for different users/teams. This workaround tend to work well as long as the number of users/teams is reasonably small.

---

<div class="post-metadata">

### Author: ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)
#### Post date: [July 10, 2015, 7:29am UTC](https://discuss.elastic.co/t/shield-drawback-please-correct-me-if-i-am-wrong/25282/3 "2015-07-10T07:29:01Z")

</div>

So , please let me know if I understand it correctly . Under kibana.yml file I can specify multiple Kibana\_index which i further assign to the users/team ? and what about LDAP integration ? Does it works with LDAP ?

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [July 10, 2015, 7:38am UTC](https://discuss.elastic.co/t/shield-drawback-please-correct-me-if-i-am-wrong/25282/4 "2015-07-10T07:38:01Z")

</div>

You can specify a single index for Kibana to use per kibana.yml file, which is why you will need a separate configuration file per team and the URL needs to be different. When you start Kibana, you can specify the configuration file to use using the '-c' parameter. You can then provide privileges to these Kibana indices to different users through Shield, which provides the integration with LDAP.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/shield-drawback-please-correct-me-if-i-am-wrong/25282/5 "2017-07-06T13:48:54Z")

</div>


