# Unable to login kibana with ldap user

**URL:** <https://forum.search-guard.com/t/unable-to-login-kibana-with-ldap-user/1623>\
**Category:** Search Guard\
**Created:** [August 19, 2019, 8:54am UTC](https://forum.search-guard.com/t/unable-to-login-kibana-with-ldap-user/1623 "2019-08-19T08:54:32Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![mattsdevop](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/mattsdevop/32/473_2.png) [@mattsdevop](https://forum.search-guard.com/u/mattsdevop)\
**Post date:** [August 19, 2019, 1:59pm UTC](https://forum.search-guard.com/t/unable-to-login-kibana-with-ldap-user/1623/4 "2019-08-19T13:59:26Z")

</div>

I experienced a similar issue after upgrading. [7.0 Upgrade assistant cluster issue needs to be resolved - #6 by mattsdevop](https://forum.search-guard.com/t/7-0-upgrade-assistant-cluster-issue-needs-to-be-resolved/1615/6)

Here’s an example of what I had to make my admin role look like following the upgrade. You’ll need to modify your sg\_roles.yml to include the following: (the tool did not do this automatically when upgraded):

```auto
Elk-Admins:
  reserved: true
  hidden: false
  description: "Migrated from v6 (all types mapped)"
  cluster_permissions:
  - "UNLIMITED"
  index_permissions:
  - index_patterns:
    - "*"
    dls: null
    fls: null
    masked_fields: null
    allowed_actions:
    - "UNLIMITED"
  tenant_permissions:
  - tenant_patterns:
    - "*"
    allowed_actions:
    - "UNLIMITED"
  - tenant_patterns:
    - "admin_tenant"
    allowed_actions:
    - "SGS_KIBANA_ALL_WRITE"
  static: false

```

---

_[View the full topic](https://forum.search-guard.com/t/unable-to-login-kibana-with-ldap-user/1623)._
