# Multi-tenant dashboards in iframe

**URL:** <https://forum.opensearch.org/t/multi-tenant-dashboards-in-iframe/21759>\
**Category:** OpenSearch\
**Tags:** discuss, troubleshoot, configure\
**Created:** [October 3, 2024, 4:25am UTC](https://forum.opensearch.org/t/multi-tenant-dashboards-in-iframe/21759 "2024-10-03T04:25:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![zhan2819](https://avatars.discourse-cdn.com/v4/letter/z/48db29/32.png) [@zhan2819](https://forum.opensearch.org/u/zhan2819)\
**Post date:** [October 3, 2024, 4:25am UTC](https://forum.opensearch.org/t/multi-tenant-dashboards-in-iframe/21759/1 "2024-10-03T04:25:25Z")

</div>

Hi guys, we are utilizing jwt token to by pass signin when embedding opensearch dashboards in iframe in our website. When embedding the dashboard, can we

1. Automatically select the tenant used
2. Prevent user from switching tenant, as datasets belonging to other clients are under other tenants in the same domain?

Thank you.

---

<div class="post-metadata">

**Author:** ![Mantas](https://avatars.discourse-cdn.com/v4/letter/m/7bcc69/32.png) [@Mantas](https://forum.opensearch.org/u/Mantas)\
**Post date:** [October 3, 2024, 10:25am UTC](https://forum.opensearch.org/t/multi-tenant-dashboards-in-iframe/21759/2 "2024-10-03T10:25:37Z")

</div>

Hi @zhan2819,

Yes, I do believe that is achievable on both points.  
On point #1, you could set the `"default_tenant" : "Private"` more info [here](https://opensearch.org/docs/latest/security/multi-tenancy/dynamic-config/#configuring-multi-tenancy-in-opensearch-dashboards). So then the user (JWT in your case) gets authorized it will get to the tenancy base on the `roles`:  
i.e:

```auto
{
  "iss": "example.com",
  "exp": 1300819380,
  "name": "John",
  "roles": "john_role"
}

```

```auto
john_role:
 reserved: false
 hidden: false
 cluster_permissions:
..
 index_permissions:
 - index_patterns:
..
 tenant_permissions:
 - tenant_patterns:
   - "John"
   allowed_actions:
   - "level of permissions needed"
 static: false
_meta:
 type: "roles"
 config_version: 2

```

And on point #2 you can disable the Global\_tenant so that the user in this case “john” can only access private tenancy (defined in the roles mapped to the user):

```auto

opendistro_security.multitenancy.tenants.enable_global: false

```

Best,  
mj
