# Defining Users to a Group and mapping the group

**URL:** <https://forum.search-guard.com/t/defining-users-to-a-group-and-mapping-the-group/451>\
**Category:** Search Guard\
**Created:** [May 10, 2017, 3:13pm UTC](https://forum.search-guard.com/t/defining-users-to-a-group-and-mapping-the-group/451 "2017-05-10T15:13:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yash](https://avatars.discourse-cdn.com/v4/letter/y/f17d59/32.png) [@Yash](https://forum.search-guard.com/u/Yash)\
**Post date:** [May 10, 2017, 3:13pm UTC](https://forum.search-guard.com/t/defining-users-to-a-group-and-mapping-the-group/451/1 "2017-05-10T15:13:30Z")

</div>

I have an query regarding granting access to the users in groups. I am not sure whether it is available in current config or not. Is there a way to map the users to a group in Searchguard.

For an instance: I have users like joe, jhon, and adam who belongs to HR

Currently I give access by mapping the user to index “sg\_roles\_mapping.yml” like

sg\_Hr\_index:

users:

- adam

- Joe

\_ Jhon

By any chance can we define like in sg\_internal-users.yml :

Hr\_group:

username1: jhon

hash: XXXXXXXX

username2 : adam

An in sg\_roles\_maping.yml

sg\_hr\_index:

users:

```
- Hr_group

```

Kindly let me know is it possible or not .

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [May 10, 2017, 3:22pm UTC](https://forum.search-guard.com/t/defining-users-to-a-group-and-mapping-the-group/451/2 "2017-05-10T15:22:35Z")

</div>

This is possible, but you need to do it the other way round.

In your intern\_users.yml, you can assign backend roles to users as well. Have a look at the sample config file we ship with Search Guard:

spock:  
hash: $2a$12$GI9JXffO3WUjTsU7Yy3E4.LBxC2ILo66Zg/rr79BpikSL2IIRezQa  
roles:  
- vulcan  
- starfleet

``

Please have also a look at the documentation regarding internal users:

[https://github.com/floragunncom/search-guard-docs/blob/master/internalusers.md](https://github.com/floragunncom/search-guard-docs/blob/master/internalusers.md)

So, you need in the sg\_internal\_users.yml something like:

joe:  
hash: …  
roles:  
- hr

adam:  
hash: …  
roles:  
- hr

``

And then in sg\_roles\_mapping.yml you would map the backend role “hr” to the Search Guard role like:

sg\_hr\_index:  
backendroles:  
- hr

``

> **···**
>
> On Wednesday, May 10, 2017 at 5:13:30 PM UTC+2, Yasvanth Babu wrote:
> 
> > I have an query regarding granting access to the users in groups. I am not sure whether it is available in current config or not. Is there a way to map the users to a group in Searchguard.
> > 
> > For an instance: I have users like joe, jhon, and adam who belongs to HR
> > 
> > Currently I give access by mapping the user to index “sg\_roles\_mapping.yml” like
> > 
> > sg\_Hr\_index:
> > 
> > users:
> > 
> > - adam
> > 
> > - Joe
> > 
> > \_ Jhon
> > 
> > By any chance can we define like in sg\_internal-users.yml :
> > 
> > Hr\_group:
> > 
> > username1: jhon
> > 
> > hash: XXXXXXXX
> > 
> > username2 : adam
> > 
> > An in sg\_roles\_maping.yml
> > 
> > sg\_hr\_index:
> > 
> > users:
> > 
> > ```
> > - Hr_group
> > 
> > ```
> > 
> > Kindly let me know is it possible or not .

---

<div class="post-metadata">

**Author:** ![Yash](https://avatars.discourse-cdn.com/v4/letter/y/f17d59/32.png) [@Yash](https://forum.search-guard.com/u/Yash)\
**Post date:** [May 10, 2017, 3:37pm UTC](https://forum.search-guard.com/t/defining-users-to-a-group-and-mapping-the-group/451/3 "2017-05-10T15:37:17Z")

</div>

I never thought of doing in different way. Will give a try. Thanks a million

> **···**
>
> On Wednesday, May 10, 2017 at 4:22:35 PM UTC+1, Jochen Kressin wrote:
> 
> > This is possible, but you need to do it the other way round.
> 
> > In your intern\_users.yml, you can assign backend roles to users as well. Have a look at the sample config file we ship with Search Guard:
> 
> > 
> 
> > spock:  
> > hash: $2a$12$GI9JXffO3WUjTsU7Yy3E4.LBxC2ILo66Zg/rr79BpikSL2IIRezQa  
> > roles:  
> > - vulcan  
> > - starfleet
> 
> > ``
> 
> > 
> 
> > Please have also a look at the documentation regarding internal users:
> 
> > 
> 
> > [https://github.com/floragunncom/search-guard-docs/blob/master/internalusers.md](https://github.com/floragunncom/search-guard-docs/blob/master/internalusers.md)
> 
> > 
> 
> > So, you need in the sg\_internal\_users.yml something like:
> 
> > joe:  
> > hash: …  
> > roles:  
> > - hr
> > 
> > adam:  
> > hash: …  
> > roles:  
> > - hr
> 
> > ``
> 
> > And then in sg\_roles\_mapping.yml you would map the backend role “hr” to the Search Guard role like:
> 
> > 
> 
> > sg\_hr\_index:  
> > backendroles:  
> > - hr
> 
> > ``
> 
> > 
> 
> > 
> 
> > On Wednesday, May 10, 2017 at 5:13:30 PM UTC+2, Yasvanth Babu wrote:
> > 
> > > I have an query regarding granting access to the users in groups. I am not sure whether it is available in current config or not. Is there a way to map the users to a group in Searchguard.
> > > 
> > > For an instance: I have users like joe, jhon, and adam who belongs to HR
> > > 
> > > Currently I give access by mapping the user to index “sg\_roles\_mapping.yml” like
> > > 
> > > sg\_Hr\_index:
> > > 
> > > users:
> > > 
> > > - adam
> > > 
> > > - Joe
> > > 
> > > \_ Jhon
> > > 
> > > By any chance can we define like in sg\_internal-users.yml :
> > > 
> > > Hr\_group:
> > > 
> > > username1: jhon
> > > 
> > > hash: XXXXXXXX
> > > 
> > > username2 : adam
> > > 
> > > An in sg\_roles\_maping.yml
> > > 
> > > sg\_hr\_index:
> > > 
> > > users:
> > > 
> > > ```
> > > - Hr_group
> > > 
> > > ```
> > > 
> > > Kindly let me know is it possible or not .
