<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security role limit ? in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Security-role-limit/m-p/118221#M25251</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;I want to create a role to create qtree and quota only (create + show) and not delete, the role will be used for PowerShell scripting.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;No problem for qtree create, show, delete is refused.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;For quota when i change one of the 4 privileges (create, delete, modify, show) the 3 others are automaticaly modified...&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;s&lt;FONT color="#0000FF"&gt;ecurity login role create -vserver SVM-TEST -role admin_qtree -cmddirname "volume qtree create" -access all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;security login role create -vserver SVM-TEST -role admin_qtree -cmddirname "volume qtree show" -access all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;security login role create -vserver SVM-TEST -role admin_qtree -cmddirname "volume quota policy rule create" -access all&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;Warning: This operation will also affect the following commands:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;"volume quota policy rule delete"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;"volume quota policy rule modify"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;"volume quota policy rule show"&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;security login role show -vserver SVM-TEST -role admin_qtree&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;Role Command/ Access&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;Vserver Name Directory Query Level&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;---------- ------------- --------- ----------------------------------- --------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree DEFAULT none&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree version readonly&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree volume qtree create all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree volume qtree show all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree volume quota policy rule create all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree volume quota policy rule delete all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree volume quota policy rule modify all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree volume quota policy rule show all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;8 entries were displayed.&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 21:26:34 GMT</pubDate>
    <dc:creator>ECOIFFE</dc:creator>
    <dc:date>2025-06-04T21:26:34Z</dc:date>
    <item>
      <title>Security role limit ?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Security-role-limit/m-p/118221#M25251</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;I want to create a role to create qtree and quota only (create + show) and not delete, the role will be used for PowerShell scripting.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;No problem for qtree create, show, delete is refused.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;For quota when i change one of the 4 privileges (create, delete, modify, show) the 3 others are automaticaly modified...&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;s&lt;FONT color="#0000FF"&gt;ecurity login role create -vserver SVM-TEST -role admin_qtree -cmddirname "volume qtree create" -access all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;security login role create -vserver SVM-TEST -role admin_qtree -cmddirname "volume qtree show" -access all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;security login role create -vserver SVM-TEST -role admin_qtree -cmddirname "volume quota policy rule create" -access all&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;Warning: This operation will also affect the following commands:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;"volume quota policy rule delete"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;"volume quota policy rule modify"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;"volume quota policy rule show"&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;security login role show -vserver SVM-TEST -role admin_qtree&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;Role Command/ Access&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;Vserver Name Directory Query Level&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;---------- ------------- --------- ----------------------------------- --------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree DEFAULT none&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree version readonly&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree volume qtree create all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree volume qtree show all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree volume quota policy rule create all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree volume quota policy rule delete all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree volume quota policy rule modify all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;SVM-TEST admin_qtree volume quota policy rule show all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;8 entries were displayed.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 21:26:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Security-role-limit/m-p/118221#M25251</guid>
      <dc:creator>ECOIFFE</dc:creator>
      <dc:date>2025-06-04T21:26:34Z</dc:date>
    </item>
  </channel>
</rss>

