Hello,
I am attempting to reduce rights to the bare minimum on local OnTAP service accounts to increase our security posture. I've created a custom role for the VSC service account that just allows for discovery, however it occurred to me that we can probably go further.
We use VSC for one single purpose only: to verify our ESX host settings match NetApp best practices. The only thing we do is browse to Overview and click Edit ESXi Host Settings when we have a new ESX host added. With this in mind: do we need an account on the cluster at all? Do we have to perform discovery if all we do is apply appropriate settings to ESX hosts? In other words: do I even need a local service account at all? Would love to hear any suggestions or thoughts!