Spring Boot Actuator Endpoints security doesn't work with custom Spring Security Configuration

This is my Spring Boot 1.5.1 Actuator application.properties:

#Spring Boot Actuator
management.contextPath: /actuator

This is my WebSecurityConfig:

public class WebSecurityConfig extends WebSecurityConfigurerAdapter {

    private UserDetailsService userDetailsService;

    private String logoutSuccessUrl;

    protected void configure(HttpSecurity http) throws Exception {

        // @formatter:off
        http.addFilterBefore(new CorsFilter(), ChannelProcessingFilter.class);

            .csrf().ignoringAntMatchers("/v1.0/**", "/logout")

            //Anyone can access the urls
        // @formatter:on

     * Configures the authentication manager bean which processes authentication requests.
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.userDetailsService(userDetailsService).passwordEncoder(new BCryptPasswordEncoder());

    public AuthenticationManager authenticationManagerBean() throws Exception {
        return super.authenticationManagerBean();


Right now I'm successfully able to login in my application with a right user that has R_0 authorities but when I trying to access for example


I receive a following error:

There was an unexpected error (type=Forbidden, status=403).
Access is denied. User must have one of the these roles: R_0

How to correctly configure Spring Boot Actuator in order to be aware about the correct Authentication ?

Right now in order to get it workin I have to do the following trick:



Is any chance to configure Actuator in a right way ?


I'm using UserDetailsService.UserDetails.Authorities

    public Collection<? extends GrantedAuthority> getAuthorities() {
        String[] authorities = permissions.stream().map(p -> {
            return p.getName();
        return AuthorityUtils.createAuthorityList(authorities);


You have to use prefix ROLE_ for your management.security.roles for example management.security.roles=ROLE_SOMENAME in order to solve this issue