# User impersonation does not work with Active directory realm

**URL:** <https://discuss.elastic.co/t/user-impersonation-does-not-work-with-active-directory-realm/91519>\
**Category:** Elasticsearch\
**Created:** [July 1, 2017, 2:07pm UTC](https://discuss.elastic.co/t/user-impersonation-does-not-work-with-active-directory-realm/91519 "2017-07-01T14:07:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [July 1, 2017, 2:07pm UTC](https://discuss.elastic.co/t/user-impersonation-does-not-work-with-active-directory-realm/91519/1 "2017-07-01T14:07:47Z")

</div>

Hi Elasticsearch team!

any news regarding the subject?  
so, basically, this does not work with active directory realm (with LDAP realm works fine, but no nested groups support):

```
curl -H "es-security-runas-user: an_ad_user" -u iis -XGET 'http://localhost:9200/'

```

(`iis` is an internal user, with `"run_as": ["*"]`)

Thanks!

P.S.: there is a couple of topics with the similar question:

> [@Elasticsearch Active Directory Authorization only support](https://discuss.elastic.co/t/elasticsearch-active-directory-authorization-only-support/87080):
>
> I wanted to know, is there any way I can configure x-pack with authorization only access. Means I should send the username only, and it will authenticate it according to the roles.

> [@Run\_as coupled with active directory auth](https://discuss.elastic.co/t/run-as-coupled-with-active-directory-auth/87068):
>
> I can't seem to get the impersonated user's ad groups reflected in xpack to acheive document label security, but instead just the user I'm authenticating to AD with. It just seems to ignore my run\_as user. Can someone please show me a snippet of config?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 3, 2017, 12:40am UTC](https://discuss.elastic.co/t/user-impersonation-does-not-work-with-active-directory-realm/91519/2 "2017-07-03T00:40:24Z")

</div>

> [@](#):
>
> any news regarding the subject?

No, the behaviour you describe has not changed in the latest releases of X-Pack and we have no announcements about any such changes.

As of right now, the AD realm requires the user's password in order to determine their groups (and consequently their roles) and the LDAP realm does not support nested groups.

---

<div class="post-metadata">

**Author:** ![jetnet](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@jetnet](https://discuss.elastic.co/u/jetnet)\
**Post date:** [July 3, 2017, 8:10am UTC](https://discuss.elastic.co/t/user-impersonation-does-not-work-with-active-directory-realm/91519/3 "2017-07-03T08:10:41Z")

</div>

Thank you for getting back to me.  
So, it's not a bug it's a limitation. Sadly, that is not mentioned on the [documentation](https://www.elastic.co/guide/en/x-pack/current/run-as-privilege.html), more over, there is a [blog article](https://www.elastic.co/blog/user-impersonation-with-x-pack-integrating-third-party-auth-with-kibana), which is optimistically hinting at possibility of impersonation with AD... That's why I spent a whole day trying to configure the thing, which does not work by design.

Do you think, it could change in the future and the impersonation feature would work with AD as well?  
Thanks!

---

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [July 5, 2017, 10:08am UTC](https://discuss.elastic.co/t/user-impersonation-does-not-work-with-active-directory-realm/91519/4 "2017-07-05T10:08:06Z")

</div>

Hi there,

I'm the product manager for X-Pack Security. I've added this feedback to my product feature data. I can't promise anything at this point, but I'll see what I can do.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2017, 10:08am UTC](https://discuss.elastic.co/t/user-impersonation-does-not-work-with-active-directory-realm/91519/5 "2017-08-02T10:08:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
