# Trying to restrict access to users so they only have dashboard access only

**URL:** <https://forum.opensearch.org/t/trying-to-restrict-access-to-users-so-they-only-have-dashboard-access-only/21979>\
**Category:** Security\
**Created:** [October 16, 2024, 3:06pm UTC](https://forum.opensearch.org/t/trying-to-restrict-access-to-users-so-they-only-have-dashboard-access-only/21979 "2024-10-16T15:06:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![nwuser](https://avatars.discourse-cdn.com/v4/letter/n/4da419/32.png) [@nwuser](https://forum.opensearch.org/u/nwuser)\
**Post date:** [October 16, 2024, 3:06pm UTC](https://forum.opensearch.org/t/trying-to-restrict-access-to-users-so-they-only-have-dashboard-access-only/21979/1 "2024-10-16T15:06:59Z")

</div>

I’m trying to restrict access for different users, so they only have dashboard access and are not able to access anything else. I’ve created the role, using the following;

PUT \_opendistro/\_security/api/roles/dashboard\_only\_role  
{  
“cluster\_permissions”: [  
“cluster\_composite\_ops\_ro”  
],  
“index\_permissions”: [  
{  
“index\_patterns”: [  
“.kibana\*”,  
“.opensearch\_dashboards\*”,  
“uat-_"  
],  
“allowed\_actions”: [  
“read”  
]  
}  
],  
“tenant\_permissions”: [  
{  
“tenant\_patterns”: [  
“global\_tenant”  
],  
“allowed\_actions”: [  
“read”  
]  
}  
],  
“kibana”: [  
{  
“base”: [],  
“feature”: {  
“dashboard”: [“read”],  
“visualize”: [“none”],  
“discover”: [“none”],  
“canvas”: [“none”],  
“maps”: [“none”],  
“management”: [“none”],  
“advancedSettings”: [“none”]  
},  
“spaces”: ["_”]  
}  
]  
}

and then created the user, using;

PUT \_opendistro/\_security/api/internalusers/restrict\_access  
{  
“password”: “the-password”,  
“opendistro\_security\_roles”: [“dashboard\_only\_role”]  
}

but when logging in, this doesn’t work and I can access the data via discover.  
I’ve also read that I may need to map the role, but when I use this;

PUT \_opendistro/\_security/api/rolesmapping/dashboard\_only\_user  
{  
backend\_roles": [“dashboard\_only\_role”]  
}

I get this error;

message" : “Role ‘dashboard\_only\_user’ is not available for role-mapping.”

Hoping someone has come across this before and can lead me in the right direction to sorting this, thanks.

---

<div class="post-metadata">

**Author:** ![Mantas](https://avatars.discourse-cdn.com/v4/letter/m/7bcc69/32.png) [@Mantas](https://forum.opensearch.org/u/Mantas)\
**Post date:** [October 17, 2024, 4:01pm UTC](https://forum.opensearch.org/t/trying-to-restrict-access-to-users-so-they-only-have-dashboard-access-only/21979/2 "2024-10-17T16:01:47Z")

</div>

Hi @nwuser,  
could you run the below and share the output:

```auto

curl -XGET "http://localhost:9200/_plugins/_security/api/roles/dashboard_only_user"

```

and

```auto

curl -XGET "http://localhost:9200/_plugins/_security/api/rolesmapping"

```

best,  
mj

---

<div class="post-metadata">

**Author:** ![nwuser](https://avatars.discourse-cdn.com/v4/letter/n/4da419/32.png) [@nwuser](https://forum.opensearch.org/u/nwuser)\
**Post date:** [October 22, 2024, 8:59am UTC](https://forum.opensearch.org/t/trying-to-restrict-access-to-users-so-they-only-have-dashboard-access-only/21979/3 "2024-10-22T08:59:47Z")

</div>

Thanks for the response @Mantas.

I only have access through “Dev Tools”, so my commands are slightly different to yours, but here is the output you asked for and I’ve just obfuscated some of the names used.

GET \_opendistro/\_security/api/roles/dashboard\_only\_role

{  
“dashboard\_only\_role” : {  
“reserved” : false,  
“hidden” : false,  
“cluster\_permissions” : [  
“cluster\_composite\_ops\_ro”  
],  
“index\_permissions” : [  
{  
“index\_patterns” : [  
“.kibana\*”,  
“.opensearch\_dashboards\*”,  
“uat-\*”  
],  
“fls” : ,  
“masked\_fields” : ,  
“allowed\_actions” : [  
“read”  
]  
}  
],  
“tenant\_permissions” : [  
{  
“tenant\_patterns” : [  
“global\_tenant”  
],  
“allowed\_actions” : [  
“kibana\_dashboard\_only”  
]  
}  
],  
“static” : false  
}  
}

GET \_opendistro/\_security/api/rolesmapping

{  
“internal\_team\_ro” : {  
“hosts” : ,  
“users” : ,  
“reserved” : false,  
“hidden” : false,  
“backend\_roles” : [  
“CN=ELK-internal-team RO,OU=Groups,OU=company-abbrev,DC=internal-team,DC=co,DC=uk”  
],  
“and\_backend\_roles” :   
},  
“logstash” : {  
“hosts” : ,  
“users” : ,  
“reserved” : false,  
“hidden” : false,  
“backend\_roles” : [  
“logstash”  
],  
“and\_backend\_roles” :   
},  
“internal\_team” : {  
“hosts” : ,  
“users” : ,  
“reserved” : false,  
“hidden” : false,  
“backend\_roles” : [  
“CN=internal-team,OU=Groups,OU=company-abbrev,DC=internal-team,DC=co,DC=uk”  
],  
“and\_backend\_roles” :   
},  
“internal\_team” : {  
“hosts” : ,  
“users” : ,  
“reserved” : false,  
“hidden” : false,  
“backend\_roles” : [  
“CN=internal-team,OU=Groups,OU=company-abbrev,DC=internal-team,DC=co,DC=uk”  
],  
“and\_backend\_roles” :   
},  
“kibana\_user” : {  
“hosts” : ,  
“users” : ,  
“reserved” : false,  
“hidden” : false,  
“backend\_roles” : [  
“CN=ELK-internal-team RO,OU=Groups,OU=company-abbrev,DC=internal-team,DC=co,DC=uk”,  
“CN=ELK-internal-team Admin,OU=Groups,OU=company-abbrev,DC=internal-team,DC=co,DC=uk”  
],  
“and\_backend\_roles” :   
},  
“security\_rest\_api\_access” : {  
“hosts” : ,  
“users” : ,  
“reserved” : false,  
“hidden” : false,  
“backend\_roles” : [  
“CN=internal-team,OU=Groups,OU=company-abbrev,DC=internal-team,DC=co,DC=uk”,  
“CN=internal-team,OU=Groups,OU=company-abbrev,DC=internal-team,DC=co,DC=uk”,  
“CN=ELK-internal-team Admin,OU=Groups,OU=company-abbrev,DC=internal-team,DC=co,DC=uk”  
],  
“and\_backend\_roles” :   
},  
“all\_access” : {  
“hosts” : ,  
“users” : ,  
“reserved” : true,  
“hidden” : false,  
“backend\_roles” : [  
“admin”  
],  
“and\_backend\_roles” : ,  
“description” : “Maps admin to all\_access”  
},  
“internal\_team\_admin” : {  
“hosts” : ,  
“users” : ,  
“reserved” : false,  
“hidden” : false,  
“backend\_roles” : [  
“CN=ELK-internal-team Admin,OU=Groups,OU=company-abbrev,DC=internal-team,DC=co,DC=uk”  
],  
“and\_backend\_roles” :   
},  
“kibana\_server\_additional” : {  
“hosts” : ,  
“users” : [  
“kibana”  
],  
“reserved” : false,  
“hidden” : false,  
“backend\_roles” : ,  
“and\_backend\_roles” :   
},  
“kibana\_server” : {  
“hosts” : ,  
“users” : [  
“kibana”  
],  
“reserved” : true,  
“hidden” : false,  
“backend\_roles” : ,  
“and\_backend\_roles” :   
}  
}

---

<div class="post-metadata">

**Author:** ![Mantas](https://avatars.discourse-cdn.com/v4/letter/m/7bcc69/32.png) [@Mantas](https://forum.opensearch.org/u/Mantas)\
**Post date:** [October 22, 2024, 11:58am UTC](https://forum.opensearch.org/t/trying-to-restrict-access-to-users-so-they-only-have-dashboard-access-only/21979/4 "2024-10-22T11:58:44Z")

</div>

> [@nwuser](#):
>
> message" : “Role ‘dashboard\_only\_user’ is not available for role-mapping.”

@nwuser, the role is named `` dashboard\_only\_role, ’ and it seems that you are trying to map` `dashboard\_only\_user.’` ?

best,  
mj

---

<div class="post-metadata">

**Author:** ![nwuser](https://avatars.discourse-cdn.com/v4/letter/n/4da419/32.png) [@nwuser](https://forum.opensearch.org/u/nwuser)\
**Post date:** [October 25, 2024, 10:32am UTC](https://forum.opensearch.org/t/trying-to-restrict-access-to-users-so-they-only-have-dashboard-access-only/21979/5 "2024-10-25T10:32:57Z")

</div>

My bad @Mantas.

I’ve rectified this and added the role to the role mapping now

{  
“dashboard\_only\_role” : {  
“hosts” : ,  
“users” : [  
“restrict\_access”  
],  
“reserved” : false,  
“hidden” : false,  
“backend\_roles” : ,  
“and\_backend\_roles” :   
}  
}

However when i still log in, it is not restricting access and this user can still access the data via “discover”

Thanks.

---

<div class="post-metadata">

**Author:** ![Mantas](https://avatars.discourse-cdn.com/v4/letter/m/7bcc69/32.png) [@Mantas](https://forum.opensearch.org/u/Mantas)\
**Post date:** [October 31, 2024, 1:13pm UTC](https://forum.opensearch.org/t/trying-to-restrict-access-to-users-so-they-only-have-dashboard-access-only/21979/6 "2024-10-31T13:13:30Z")

</div>

@nwuser, that is correct, you control the index level permission (needed for dashboards) once the permissions are granted user will be able to access it (dashboards, discovery, dev tools, curl,…)

best,  
mj
