Access control

Control what each user can view and do by assigning privileges to their roles. Each feature has its own privileges, so review them when you turn on a new feature, or when your team or its responsibilities change.

In Elastic Stack, you create roles and assign Kibana feature privileges, index privileges, and cluster privileges to them. In Serverless, you assign a predefined Security user role, or create a custom role with the privileges you need.

Most Elastic Security features use Kibana feature privileges, which you set to All, Read, or None for each feature. Some features also need index privileges on the indices that store their data, such as the alert indices for your space.

Keep these points in mind when you create roles:

  • Elastic Defend uses sub-feature privileges: Selecting All for the Security feature doesn't grant access to Elastic Defend features such as endpoint management, host isolation, or trusted applications. To grant them, turn on Customize sub-feature privileges and set each one.
  • Rules and alerts have separate privileges: New custom roles need explicit Rules and Exceptions and Alerts privileges. After you upgrade, check that existing custom roles still have the access to alerts that you expect.
  • Privileges can apply per space: You can assign Elastic Defend privileges for each Kibana space. To manage artifacts that apply to all policies, users need the Global Artifact Management privilege.
Your goal Start here
Give users access to endpoint management, response actions, and artifacts Elastic Defend feature privileges
Give users access to detection rules, alerts, and exceptions Detections privileges
Give users access to Attack Discovery and its schedules Attack Discovery privileges
Check which privileges let users manage endpoint artifacts in each space Spaces and Elastic Defend FAQ: RBAC
Check what you need for cloud security features CSPM privilege requirements or CNVM privilege requirements
Check what you need for entity analytics Entity analytics requirements

After you set up roles, you can: