Skip to content

Manage users and roles

Use named identities and least-privilege access for normal platform use.

Do not use the Elasticsearch administrator account for routine application access, dashboards, data ingestion, or day-to-day user activity.

Choose the access type

Use the access method that matches the workload:

Access type Use for
Named Elastic user Individual users when local authentication is required
Single sign-on Organization users authenticated through the configured identity provider
API key Applications, integrations, agents, and automated processes
Administrator account Initial setup, recovery, and tasks requiring elevated privileges

For organization-wide user access, consider configuring single sign-on.

Create a role

In Kibana:

  1. Sign in with an account authorized to manage security.
  2. Open Roles.
  3. Create a role for the required workload.
  4. Grant only the required Elasticsearch cluster and index privileges.
  5. Grant access only to the required Kibana spaces and features.
  6. Save the role.

Common role patterns include:

  • read-only access;
  • data ingestion;
  • dashboard and visualization users;
  • content administrators;
  • platform administrators.

Avoid granting broad cluster or index privileges when narrower access is sufficient.

Create or assign a user

For a local Elastic user:

  1. Open Users in Kibana.
  2. Create the user.
  3. Assign the appropriate role or roles.
  4. Save the user.
  5. Sign in with the new account and verify the required access.

Also verify that the user cannot perform operations that should not be permitted.

For SSO users, access is normally controlled through identity-provider groups and Elastic role mappings rather than creating individual local accounts.

Application access

For applications and automated integrations, prefer an API key or another supported scoped credential instead of a shared administrator password.

Grant only the permissions required by the application.

Store application credentials in your organization's approved secrets-management system.

Protect credentials

  • Do not share administrator accounts.
  • Store passwords and API keys in an approved secrets-management system.
  • Rotate credentials when they are no longer required or exposure is suspected.
  • Remove or disable access when a user or application no longer needs it.
  • Never include passwords, authentication headers, or API keys in support tickets or documentation.

Learn more

For detailed Elasticsearch security behavior and privilege definitions, see the Elastic documentation for user authentication and role management.

Next, continue with configure single sign-on if your organization uses centralized authentication.