Security

How to create an superpower role that is able to add a restricted list of roles to users?

francoisternois
Path Finder

Hello,

I would like to create a role which allows to add roles to users on a limited perimeter. The goal is to delegate a part of the user/role mapping to superpowerusers according to their perimeter.

For example:
user1 can add as role only role1 (no any other role)

I have already tried with the following authorize.conf configurations

[role_superpoweruser]
edit_user = enabled
edit_roles_grantable=enabled
grantableRoles = role1;
=> allows to add ALL roles (including others than role1)

[role_superpoweruser]
edit_user = enabled
grantableRoles = role1;
=> the user can add role1 but it removes ALL other roles

Any help would be greatly appreciated

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @francoisternois,

for my knowledge it isn't possible because the grant to add role is on/off , you canod give the possibility to add only some roles.

ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @francoisternois,

for my knowledge it isn't possible because the grant to add role is on/off , you canod give the possibility to add only some roles.

ciao.

Giuseppe

francoisternois
Path Finder

Thank you for your answer.

It would be very useful 😕

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @francoisternois ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...