# X-pack 5.4.1 Role mapping not getting applied on AD users

**URL:** <https://discuss.elastic.co/t/x-pack-5-4-1-role-mapping-not-getting-applied-on-ad-users/92049>\
**Category:** Elasticsearch\
**Created:** [July 6, 2017, 8:25am UTC](https://discuss.elastic.co/t/x-pack-5-4-1-role-mapping-not-getting-applied-on-ad-users/92049 "2017-07-06T08:25:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![venuambati](https://avatars.discourse-cdn.com/v4/letter/v/49beb7/32.png) [@venuambati](https://discuss.elastic.co/u/venuambati)\
**Post date:** [July 6, 2017, 8:25am UTC](https://discuss.elastic.co/t/x-pack-5-4-1-role-mapping-not-getting-applied-on-ad-users/92049/1 "2017-07-06T08:25:10Z")

</div>

I am using ELK and x-pack 5.4.1 version. I am using AD authentication using x-pack. System is allowing me to login But getting this error.

```
Config: Error 403 Forbidden: [security_exception] action [indices:data/write/update] is unauthorized for user <user name error>"

```

I have defined roles in Kibana and Role mapping in "/config/x-pack/role\_mapping.yml" file. These roles are not getting applied when login.

PFB the elasticsearch.yml configuration.

```
    xpack.security.audit.enabled: true
   xpack:
  security:
    authc:
      realms:
       active_directory:
        type: active_directory
        order: 0
        domain_name: "<domain_name>"
        url: ldap://<ldaphost>:389
        unmapped_groups_as_roles: true
        #follow_referrals: false
        user_search:
         filter: "(&(objectClass=user)(sAMAccountName={0}))"
        files:
            role_mapping: "<Config Dir>/x-pack/role_mapping.yml"

```

role\_mapping.yml

```
superuser:
  - "cn=<user name>,cn=Users,dc=<domain>,dc=com"

```

Access Logs:

```
[2017-07-06T12:21:44,998] [transport] [access_granted] origin_type=[rest], origin_address=[<IP>], principal=[<user name>], action=[cluster:admin/xpack/security/user/authenticate], request=[AuthenticateRequest]
[2017-07-06T12:21:45,000] [transport] [access_denied] origin_type=[rest], origin_address=[<IP>], principal=[<user name>], action=[indices:data/read/search], indices=[.reporting-*], request=[SearchRequest]

```

Any help appreciated. Thanks in advance.

Regards  
Venu

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 7, 2017, 2:51am UTC](https://discuss.elastic.co/t/x-pack-5-4-1-role-mapping-not-getting-applied-on-ad-users/92049/2 "2017-07-07T02:51:59Z")

</div>

There are 2 likely explanations:

1. That the DN in your role\_mapping.yml file is not the right match for your user.
2. That the path to your role\_mapping file is incorrect.

Because you've redacted those in your post, it's hard to tell whether either of those are the cause, but they're the most likely.

To diagnose #1, try to `GET``/_xpack/security/_authenticate?pretty` as the user you're trying to map to `superuser`.  
The result of that API will tell you the DN and groups that your user is in, you can then check that these are the same as you have entered in your role\_mapping file.

To diagnose #2, check the elasticsearch logs.  
Check for messages for the `DnRoleMapper` category, if there is a problem with your file it will be logged there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 4, 2017, 2:52am UTC](https://discuss.elastic.co/t/x-pack-5-4-1-role-mapping-not-getting-applied-on-ad-users/92049/3 "2017-08-04T02:52:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
