# User Creation can do All users

**URL:** https://discuss.elastic.co/t/user-creation-can-do-all-users/307840
**Category:** Kibana
**Created:** [June 22, 2022, 8:01am UTC](https://discuss.elastic.co/t/user-creation-can-do-all-users/307840 "2022-06-22T08:01:56Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Muhammed\_Ashique](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muhammed_ashique/32/98686_2.png) [@Muhammed\_Ashique](https://discuss.elastic.co/u/Muhammed_Ashique)
#### Post date: [June 22, 2022, 8:01am UTC](https://discuss.elastic.co/t/user-creation-can-do-all-users/307840/1 "2022-06-22T08:01:56Z")

</div>

I have created a user and this user is login via SSO . But the users who login via sso all users can manage user and Role session under stack management. How can i restrict/disable User creation functionalities for a user.

Note:- When i do normal authenticatio (user,password) method i can able to archive this

---

<div class="post-metadata">

### Author: ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)
#### Post date: [June 28, 2022, 2:35pm UTC](https://discuss.elastic.co/t/user-creation-can-do-all-users/307840/2 "2022-06-28T14:35:05Z")

</div>

This is probably related with the roles assigned to the user you are creating. You should check which roles your SSO user has and probably adjust the default settings as explained here

> **[Configuring SAML single-sign-on on the Elastic Stack | Elasticsearch Guide...](https://www.elastic.co/guide/en/elasticsearch/reference/current/saml-guide-stack.html#saml-role-mapping)**

I guess you need to first create a role with the explicit permissions you want to grant to your SSO users and then ensure that is the **only** role granted by default to any user logging through SSO.

---

<div class="post-metadata">

### Author: ![Muhammed\_Ashique](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muhammed_ashique/32/98686_2.png) [@Muhammed\_Ashique](https://discuss.elastic.co/u/Muhammed_Ashique)
#### Post date: [July 13, 2022, 4:45pm UTC](https://discuss.elastic.co/t/user-creation-can-do-all-users/307840/3 "2022-07-13T16:45:06Z")

</div>

I used same mechanism only. but still it is listing the user and roles tab. do we have any other mechanism ?. successfully can do while setting up the authentication via basic. this issue facing while SSO. We are using pingfederate as SSO

---

<div class="post-metadata">

### Author: ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)
#### Post date: [July 14, 2022, 7:56am UTC](https://discuss.elastic.co/t/user-creation-can-do-all-users/307840/4 "2022-07-14T07:56:12Z")

</div>

Both [SAML](https://www.elastic.co/guide/en/elasticsearch/reference/current/saml-guide-stack.html#saml-role-mapping) and [OpenId](https://www.elastic.co/guide/en/elasticsearch/reference/current/oidc-guide.html#oidc-role-mappings) set ups expect you to configure the **role mappings** to provide the correct authorization once users have been authenticated.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 11, 2022, 7:56am UTC](https://discuss.elastic.co/t/user-creation-can-do-all-users/307840/5 "2022-08-11T07:56:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
