Security

How to create user who can create user without administrative right ?

akanno
Communicator

Hi,splunk community.

I'm now considering user management.

I want to create user who can only do user management without administrative right.
Therefore, I created a new user, and I added "edit_user" and "edit_role" to Capabilities of this user.

It looks like I created the user who do user management without administrative right.
However, this user can create user who have administrative right.
That really doesn't have any meaning.

is there a way to prevent to create user who have administrative right?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

The best way is to outsource user management via LDAP or Active Directory. The Splunk administrator sets up the connection and maps Splunk roles to LDAP/AD groups, and users are added/removed from Splunk by adding them to those LDAP/AD groups or removing them.

With the built-in authentication you're not going to achieve that, there's no special capability that restricts assigning roles with admin permissions to users, and nothing restricting assigning admin capabilities to roles.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

The best way is to outsource user management via LDAP or Active Directory. The Splunk administrator sets up the connection and maps Splunk roles to LDAP/AD groups, and users are added/removed from Splunk by adding them to those LDAP/AD groups or removing them.

With the built-in authentication you're not going to achieve that, there's no special capability that restricts assigning roles with admin permissions to users, and nothing restricting assigning admin capabilities to roles.

akanno
Communicator

Thank you for your help.
I will use LDAP or AD.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...