﻿---
title: Access control
description: Review the privileges that Elastic Security features require, including Elastic Defend, detections, and Attack Discovery.
url: https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/manage/access-control
products:
  - Elastic Cloud Serverless
  - Elastic Documentation
  - Elastic Security
applies_to:
  - Serverless Security projects: Generally available
  - Elastic Stack: Generally available
---

# Access control
Control what each user can view and do by assigning privileges to their roles. Each feature has its own privileges, so review them when you turn on a new feature, or when your team or its responsibilities change.
In Elastic Stack, you create roles and assign Kibana feature privileges, index privileges, and cluster privileges to them. In Serverless, you assign a predefined Security user role, or create a custom role with the privileges you need.

## How Elastic Security privileges work

Most Elastic Security features use Kibana feature privileges, which you set to **All**, **Read**, or **None** for each feature. Some features also need index privileges on the indices that store their data, such as the alert indices for your space.
Keep these points in mind when you create roles:
- **Elastic Defend uses sub-feature privileges**: Selecting **All** for the **Security** feature doesn't grant access to Elastic Defend features such as endpoint management, host isolation, or trusted applications. To grant them, turn on **Customize sub-feature privileges** and set each one.
- <applies-to>Elastic Stack: Generally available since 9.4</applies-to> **Rules and alerts have separate privileges**: New custom roles need explicit **Rules and Exceptions** and **Alerts** privileges. After you upgrade, check that existing custom roles still have the access to alerts that you expect.
- <applies-to>Elastic Stack: Generally available since 9.1</applies-to> **Privileges can apply per space**: You can assign Elastic Defend privileges for each Kibana space. To manage artifacts that apply to all policies, users need the **Global Artifact Management** privilege.


## Where to start


| Your goal                                                                                                                          | Start here                                                                                                                                                                                                                                                                             |
|------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Give users access to endpoint management, response actions, and artifacts                                                          | [Elastic Defend feature privileges](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/configure-elastic-defend/elastic-defend-feature-privileges)                                                                                                               |
| Give users access to detection rules, alerts, and exceptions                                                                       | [Detections privileges](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/detect-and-alert/detections-privileges)                                                                                                                                               |
| Give users access to Attack Discovery and its schedules                                                                            | [Attack Discovery privileges](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/ai/attack-discovery/grant-access)                                                                                                                                               |
| <applies-to>Elastic Stack: Preview since 9.1</applies-to> Check which privileges let users manage endpoint artifacts in each space | [Spaces and Elastic Defend FAQ: RBAC](/elastic/docs-builder/docs/4384/solutions/security/get-started/spaces-defend-faq#spaces-security-faq-rbac)                                                                                                                                       |
| Check what you need for cloud security features                                                                                    | [CSPM privilege requirements](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/cloud/cspm-privilege-requirements) or [CNVM privilege requirements](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/cloud/cnvm-privilege-requirements) |
| Check what you need for entity analytics                                                                                           | [Entity analytics requirements](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/advanced-entity-analytics/entity-analytics-requirements)                                                                                                                      |


## Next steps

After you set up roles, you can:
- [Configure workspace settings](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/manage/configure-workspace-settings) to organize security content into spaces.
- Learn how to [manage Kibana roles](https://www.elastic.co/elastic/docs-builder/docs/4384/deploy-manage/users-roles/cluster-or-deployment-auth/kibana-role-management) in Elastic Stack, or [custom roles](https://www.elastic.co/elastic/docs-builder/docs/4384/deploy-manage/users-roles/cloud-organization/user-roles) in Serverless.