# Index Level Permissions

**URL:** <https://forum.opensearch.org/t/index-level-permissions/23318>\
**Category:** Security\
**Tags:** troubleshoot\
**Created:** [February 4, 2025, 8:35pm UTC](https://forum.opensearch.org/t/index-level-permissions/23318 "2025-02-04T20:35:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![JohnHarris](https://avatars.discourse-cdn.com/v4/letter/j/a8b319/32.png) [@JohnHarris](https://forum.opensearch.org/u/JohnHarris)\
**Post date:** [February 4, 2025, 8:35pm UTC](https://forum.opensearch.org/t/index-level-permissions/23318/1 "2025-02-04T20:35:06Z")

</div>

**Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):  
2.17

**Describe the issue** :  
I am not able to limit the indexes queried using index permissions.

I have several user roles that map to different index patterns (e.g., `email-*`) and these are mapped to backend IAM Roles. I may be misunderstanding how this works, but my hope was to perform a search on all indexes (using `/_search`) and let the role’s inherited index permissions limit the query. Instead I am getting the error down below. When I manually specify the index pattern for the user (`/email-*/_search`) in my function then everything works, but I want to avoid having to specify the search index.

**Configuration** :

```auto
email-role:
  cluster_permissions:
  index_permissions:
  - index_patterns:
    - "email-*"
    allowed_actions:
    - "read"
    - "search"
    - "indices:data/read/search"
  tenant_permissions:

```

```auto
email-role:
  backend_roles:
  - "arn:aws:iam::123:role/EmailRole"
  hosts: []
  users:

```

**Relevant Logs or Screenshots** :  
Error log:

```auto
no permissions for [indices:data/read/search] and User [name=arn:aws-:iam::123:role/EmailRole, backend_roles=[arn:aws:iam::123:role/EmailRole], requestedTenant=null]

```

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [February 5, 2025, 9:26am UTC](https://forum.opensearch.org/t/index-level-permissions/23318/2 "2025-02-05T09:26:26Z")

</div>

@JohnHarris Have you tried using `do_not_fail_on_forbidden` option?

> **[Permissions](https://opensearch.org/docs/latest/security/access-control/permissions/#do_not_fail_on_forbidden)**
>
> Permissions

---

<div class="post-metadata">

**Author:** ![JohnHarris](https://avatars.discourse-cdn.com/v4/letter/j/a8b319/32.png) [@JohnHarris](https://forum.opensearch.org/u/JohnHarris)\
**Post date:** [February 7, 2025, 2:07am UTC](https://forum.opensearch.org/t/index-level-permissions/23318/3 "2025-02-07T02:07:10Z")

</div>

Ah yes that’s what I was looking for. Thank you!
