# X-Pack Security - Created Role not Apply to AD Users

**URL:** https://discuss.elastic.co/t/x-pack-security-created-role-not-apply-to-ad-users/129341
**Category:** Elasticsearch
**Created:** [April 24, 2018, 3:50pm UTC](https://discuss.elastic.co/t/x-pack-security-created-role-not-apply-to-ad-users/129341 "2018-04-24T15:50:22Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![FoxCrash](https://avatars.discourse-cdn.com/v4/letter/f/aeb1de/32.png) [@FoxCrash](https://discuss.elastic.co/u/FoxCrash)
#### Post date: [April 24, 2018, 3:50pm UTC](https://discuss.elastic.co/t/x-pack-security-created-role-not-apply-to-ad-users/129341/1 "2018-04-24T15:50:22Z")

</div>

I have installed a cluster ELK on a VM:

- Logstash 5.4.0
- ElasticSearch 5.4.0
- Kibana 5.4.0

I have installed X-Pack on each nodes of the cluster and I can connect to kibana with any users of my AD. Here the **elasticsearch.yml**

```
xpack:
      security:
     authc:
       realms:
        active_directory:
         type: active_directory
         order: 0
         domain_name: my.domain
         url: ldap://@IP:XXX
         unmapped_groups_as_roles: false
         user_search.base_dn: "ou=users,dc=my,dc=domain"
         user_search:
          filter: "(&(objectClass=user)(sAMAccountName={0}))"
         files: 
           role_mapping: /etc/elasticsearch/x-pack/role_mapping.yml

```

I have mapped users with built-in roles provided by Elasticsearch and it works. Here the **role\_mapping.yml** :

```
// Built-In Role - It Works ! //
//kibana_user:
// - "cn=CARTES John,ou=users,dc=my,dc=domain"

// Personalized Roles - It doesn't work //
clicks_admin:
 - "cn=CARTES John,ou=users,dc=my,dc=domain"

```

I also created a role name clicks\_admin with the API REST of Elasticsearch:

```
{
"clicks_admin" : {
  "cluster" : [
    "all"
  ],
  "indices" : [
    {
      "names" : [
        "eventmanager2.0_data"
      ],
      "privileges" : [
        "all"
      ],
      "field_security" : {
        "grant" : [
          "eventmanager_event_type",
          "source",
          "beat.hostname.keyword",
          "beat.version"
        ]
      }
    }
  ],
  "run_as" : [],
  "metadata" : { },
  "transient_metadata" : {
    "enabled" : true
  }
}
}

```

But when I want to connect to kibana using an AD User that I have mapped with the role clicks\_admin. It says **Config: Error 403 Forbidden: [security\_exception] action [indices:data/write/update] is unauthorized for user [jcartais]**.

Whereas when I search through the logs of elasticsearch everythings seems to be fine. Here the logs of elasticsearch during it's start and when I try to connect via Kibana with an AD user :

```
 [2018-04-24T16:58:42,469][DEBUG][o.e.x.s.a.s.DnRoleMapper] [myServerElasticSearch] [1] role mappings found in file [/etc/elasticsearch/x-pack/role_mapping.yml] for realm [active_directory/active_directory]

... (parts omitted)

[2018-04-24T16:59:06,785][DEBUG][o.e.x.s.a.l.LdapRealm] [myServerElasticSearch] user [jcartes] not found in cache for realm [active_directory], proceeding with normal authentication

[2018-04-24T16:59:06,874][DEBUG][o.e.x.s.a.l.ActiveDirectorySessionFactory] [lancyelasticdevsi01.ancy.fr.sopra] group SID to DN [cn=CARTES John,ou=users,dc=my,dc=domain] search filter: [(|(objectSid=...))]

[2018-04-24T16:59:07,106][DEBUG][o.e.x.s.a.s.DnRoleMapper] [myServerElasticSearch] the roles [[]], are mapped from these [active_directory] groups [[My_AD_Groups]] for realm [active_directory/active_directory]

[2018-04-24T16:59:07,107][DEBUG][o.e.x.s.a.s.DnRoleMapper] [myServerElasticSearch] the roles [[clicks_admin]], are mapped from the user [cn=CARTES John,ou=users,dc=my,dc=domain] for realm [active_directory/active_directory]

[2018-04-24T16:59:07,114][DEBUG][o.e.x.s.a.l.LdapRealm] [myServerElasticSearch] realm [active_directory] authenticated user [jcartais], with roles [[clicks_admin]]

[2018-04-24T16:59:07,449][DEBUG][o.e.x.s.a.e.ReservedRealm] [myServerElasticSearch] user [jcartes] not found in cache for realm [reserved], proceeding with normal authentication

 ...

 [2018-04-24T16:59:08,475][DEBUG][o.e.x.s.a.e.ReservedRealm] [myServerElasticSearch] user [jcartes] not found in cache for realm [reserved], proceeding with normal authentication

[2018-04-24T16:59:08,476][DEBUG][o.e.x.s.a.l.LdapRealm] [myServerElasticSearch] realm [active_directory] authenticated user [jcartes], with roles [[clicks_admin]]

```

Can you please look at this. If you need any additionnal informations please tell me.

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [April 24, 2018, 11:57pm UTC](https://discuss.elastic.co/t/x-pack-security-created-role-not-apply-to-ad-users/129341/2 "2018-04-24T23:57:40Z")

</div>

Please take the time to format your post so that it is as easy to read as possible. You should use the `</>` button for config files or JSON bodies. When a post is easy to read, people are more likely to take the time to follow along and help you.

> [@FoxCrash](#):
>
> Forbidden: [security\_exception] action [indices:data/write/update] is unauthorized for user [jcartais]/\>.

This message is accurate. Your `clicks_admin` role does not have access to Kibana.  
You need to grant the `kibana_user` role as well as `clocks_admin`.  
See [Kibana and Security | X-Pack for the Elastic Stack [5.4] | Elastic](https://www.elastic.co/guide/en/x-pack/5.4/kibana.html)

---

<div class="post-metadata">

### Author: ![FoxCrash](https://avatars.discourse-cdn.com/v4/letter/f/aeb1de/32.png) [@FoxCrash](https://discuss.elastic.co/u/FoxCrash)
#### Post date: [April 25, 2018, 7:03am UTC](https://discuss.elastic.co/t/x-pack-security-created-role-not-apply-to-ad-users/129341/3 "2018-04-25T07:03:56Z")

</div>

Thanks for your response. Sorry for the formatting of my message it's the first time I post a message on this platform 😅.

So I just have to decomment the **kibana\_user** section in my **role\_mapping.yml**. In order for my AD user to be able to connect to kibana ?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 23, 2018, 7:04am UTC](https://discuss.elastic.co/t/x-pack-security-created-role-not-apply-to-ad-users/129341/4 "2018-05-23T07:04:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
