<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OnTAP Custom Role Not Working in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163443#M37385</link>
    <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/45689"&gt;@paul_stejskal&lt;/a&gt;&amp;nbsp;unfortunately that command didn't do the trick. I may experiment with some other security login commands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/81067"&gt;@jcolonfzenpr&lt;/a&gt;&amp;nbsp;thank you for showing me your testing of my issue! Do you have a suggestion for how to get the desired results?&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jan 2021 16:56:29 GMT</pubDate>
    <dc:creator>TMADOCTHOMAS</dc:creator>
    <dc:date>2021-01-28T16:56:29Z</dc:date>
    <item>
      <title>OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163393#M37361</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to create a custom role to limit the rights of a domain-based service account we use exclusively to run PowerShell scripts. The role resides in the main cluster SVM and I've only given it rights to change the replication throttle setting as shown below. I assigned the role to the service account with the applications ssh and ontapi. When testing, it immediately generated this error: "Insufficient privileges: user '&amp;lt;username&amp;gt;' does not have read access to this resource".&amp;nbsp; Apparently I need to give at least read only access to a certain command to allow it to log on in the first place. Does anyone know what that would be?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Role Name: script&lt;BR /&gt;Command / Directory: vserver options&lt;BR /&gt;Access Level: all&lt;BR /&gt;Query: -option-name replication.throttle.outgoing.max_kbs&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:37:14 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163393#M37361</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2025-06-04T10:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163432#M37379</link>
      <description>&lt;P&gt;What is the security login show output? And did you set up a security login show?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 15:20:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163432#M37379</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2021-01-28T15:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163434#M37381</link>
      <description>&lt;P&gt;The service account has two entries, one for the ontapi application and one for the ssh application. Previously the role was set at admin, and I just changed the role to the new 'script' role with limited rights to see if it would work. I manually ran the script both before and after the change. While set to admin it worked fine of course, but when I switched it to the new role, it generated the error I mentioned. I think there's a command path I need to give read only access to but don't know what that would be.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 15:30:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163434#M37381</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2021-01-28T15:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163438#M37382</link>
      <description>It's probably security login role command. I think you've got the right idea it's in the "options" output.</description>
      <pubDate>Thu, 28 Jan 2021 16:23:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163438#M37382</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2021-01-28T16:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163439#M37383</link>
      <description>&lt;P&gt;That's a possibility. I guess it has to read the role to know what it's rights are :). I'll try that and update the thread with the results.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 16:26:54 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163439#M37383</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2021-01-28T16:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163440#M37384</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Defining custom roles:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.pow-adm-auth-rbac%2FGUID-910E18E9-B83C-41BF-8A68-C1806FEB6177.html" target="_blank" rel="noopener"&gt;https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.pow-adm-auth-rbac%2FGUID-910E18E9-B83C-41BF-8A68-C1806FEB6177.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cluster1::&amp;gt; &lt;STRONG&gt;security login role create -role script -cmddirname "vserver" -access readonly -vserver cluster1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;cluster1::&amp;gt; &lt;STRONG&gt;security login role create -role script -cmddirname "vserver options" -access all -query "-option-name replication.throttle.outgoing.max_kbs" -vserver cluster1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;cluster1::&amp;gt; security login create -user-or-group-name jocolon -application ssh -authentication-method password -role script -vserver cluster1&lt;/P&gt;&lt;P&gt;cluster1::&amp;gt; security login create -user-or-group-name jocolon -application console -authentication-method password -role script -vserver cluster1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I logged in as jocolon user with script role assigned&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;cluster1::&amp;gt; &lt;STRONG&gt;vserver options -vserver cluster1 -option-name&lt;/STRONG&gt;&lt;BR /&gt;encryption.data_at_rest_encryption.disable_by_default&lt;BR /&gt;replication.create_data_protection_rels.enable&lt;BR /&gt;replication.dst_snapshot_op_ems.enable&lt;BR /&gt;replication.feature1.enable&lt;BR /&gt;replication.ls_mirrors_on_data_volumes.enable&lt;BR /&gt;replication.mirror_initialize_priority&lt;BR /&gt;replication.mirror_update_priority&lt;BR /&gt;replication.reservation.dst.high_pri_xfer_pct&lt;BR /&gt;replication.reservation.dst.low_pri_xfer_pct&lt;BR /&gt;replication.reservation.src.high_pri_xfer_pct&lt;BR /&gt;replication.reservation.src.low_pri_xfer_pct&lt;BR /&gt;replication.restore_priority&lt;BR /&gt;replication.throttle.enable&lt;BR /&gt;replication.throttle.incoming.max_kbs&lt;BR /&gt;replication.throttle.outgoing.max_kbs&lt;BR /&gt;replication.throttle.outgoing.max_kbs_objstore&lt;BR /&gt;replication.vault_initialize_priority&lt;BR /&gt;replication.vault_update_priority&lt;BR /&gt;snmp.enable&lt;BR /&gt;volmove.throttle.enable&lt;/P&gt;&lt;P&gt;cluster1::&amp;gt; &lt;STRONG&gt;vserver options -vserver cluster1 -option-name replication.throttle.outgoing.max_kbs -option-value 45&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;cluster1::&amp;gt; vserver options -vserver cluster1 -option-name replication.throttle.outgoing.max_kbs&lt;/P&gt;&lt;P&gt;cluster1&lt;BR /&gt;&lt;STRONG&gt;replication.throttle.outgoing.max_kbs &lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;45 -&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;cluster1::&amp;gt; vserver options -vserver cluster1 -option-name&lt;STRONG&gt; replication.throttle.incoming.max_kbs&lt;/STRONG&gt; -option-value 2&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Error: command failed: not authorized for that command&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;cluster1::&amp;gt; &lt;STRONG&gt;?&lt;/STRONG&gt;&lt;BR /&gt;exit Quit the CLI session&lt;BR /&gt;history Show the history of commands for this CLI session&lt;BR /&gt;man Display the on-line manual pages&lt;BR /&gt;redo Execute a previous command&lt;BR /&gt;rows Show/Set the rows for this CLI session&lt;BR /&gt;top Go to the top-level directory&lt;BR /&gt;up Go up one directory&lt;BR /&gt;&lt;STRONG&gt;vserver&amp;gt; Manage Vservers&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;cluster1::&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 16:41:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163440#M37384</guid>
      <dc:creator>jcolonfzenpr</dc:creator>
      <dc:date>2021-01-28T16:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163443#M37385</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/45689"&gt;@paul_stejskal&lt;/a&gt;&amp;nbsp;unfortunately that command didn't do the trick. I may experiment with some other security login commands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/81067"&gt;@jcolonfzenpr&lt;/a&gt;&amp;nbsp;thank you for showing me your testing of my issue! Do you have a suggestion for how to get the desired results?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 16:56:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163443#M37385</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2021-01-28T16:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163444#M37386</link>
      <description>&lt;P&gt;can you share the powershell script?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 17:04:52 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163444#M37386</guid>
      <dc:creator>jcolonfzenpr</dc:creator>
      <dc:date>2021-01-28T17:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163487#M37396</link>
      <description>&lt;P&gt;Yes, here it is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# Import the OnTAP module and create the cluster connection variable&lt;BR /&gt;Clear-Host&lt;BR /&gt;Import-Module DataONTAP&lt;BR /&gt;$CLUSTER = Connect-NcController -Name &amp;lt;cluster_name&amp;gt;&lt;/P&gt;&lt;P&gt;# Throttle snapmirror transfers&lt;BR /&gt;Invoke-NaSsh -Name $CLUSTER -Command "options -option-name replication.throttle.outgoing.max_kbs 3125"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's the one for throttling. The one for unthrottle is the same except "unlimited" at the end instead of 3125. This is used on multiple remote offices and works fine as long as the account has full admin rights. I'm trying to reduce the service account rights down to just the ones it needs to perform the task.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 21:05:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163487#M37396</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2021-01-29T21:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163488#M37397</link>
      <description>&lt;P&gt;It's getting hung up here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$CLUSTER = Connect-NcController -Name albflnacl01p&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error says :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Connect-NcController : Insufficient privileges: user '&amp;lt;username&amp;gt;' does not have read access to this resource&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the role. As you can see I tried setting the command/directory to "security login" but that didn't work either.&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Vserver: &amp;lt;vserver&amp;gt;&lt;BR /&gt;Role Name: script&lt;BR /&gt;Command / Directory: DEFAULT&lt;BR /&gt;Access Level: none&lt;BR /&gt;Query:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Vserver: &amp;lt;vserver&amp;gt;&lt;BR /&gt;Role Name: script&lt;BR /&gt;Command / Directory: security login&lt;BR /&gt;Access Level: readonly&lt;BR /&gt;Query:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Vserver: &amp;lt;vserver&amp;gt;&lt;BR /&gt;Role Name: script&lt;BR /&gt;Command / Directory: vserver options&lt;BR /&gt;Access Level: all&lt;BR /&gt;Query: -option-name replication.throttle.outgoing.max_kbs&lt;BR /&gt;----------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas or suggestions?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 21:15:19 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163488#M37397</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2021-01-29T21:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163491#M37398</link>
      <description>&lt;P&gt;&lt;SPAN&gt;can you add one extra role setting like this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Vserver: &amp;lt;vserver&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Role Name: script&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Command / Directory: &lt;STRONG&gt;vserver&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Access Level: &lt;STRONG&gt;readonly&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Query:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 21:41:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163491#M37398</guid>
      <dc:creator>jcolonfzenpr</dc:creator>
      <dc:date>2021-01-29T21:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163492#M37399</link>
      <description>&lt;P&gt;FYI I found the following which answers my question for 7-mode. Anyone know a cdot equivalent?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.netapp.com/t5/Microsoft-Virtualization-Discussions/Determining-Ontap-privileges-needed-for-powershell-script/td-p/16210" target="_blank"&gt;https://community.netapp.com/t5/Microsoft-Virtualization-Discussions/Determining-Ontap-privileges-needed-for-powershell-script/td-p/16210&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/81067"&gt;@jcolonfzenpr&lt;/a&gt;&amp;nbsp;I will try that and see if it works.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 21:44:09 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163492#M37399</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2021-01-29T21:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163493#M37400</link>
      <description>&lt;P&gt;&lt;SPAN&gt;i think this is not needed!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Vserver: &amp;lt;vserver&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Role Name: script&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Command / Directory: security login&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Access Level: readonly&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Query:&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 21:46:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163493#M37400</guid>
      <dc:creator>jcolonfzenpr</dc:creator>
      <dc:date>2021-01-29T21:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163505#M37408</link>
      <description>&lt;P&gt;I do the testing and it work by adding a role setting to the &lt;STRONG&gt;DEFAULT&lt;/STRONG&gt; as &lt;STRONG&gt;readonly&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Security role creation:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;security login role create -role script -cmddirname "&lt;STRONG&gt;DEFAULT&lt;/STRONG&gt;" -access &lt;STRONG&gt;readonly&lt;/STRONG&gt; -vserver cluster1&lt;BR /&gt;security login role create -role script -cmddirname "&lt;STRONG&gt;vserver&lt;/STRONG&gt;" -access &lt;STRONG&gt;readonly&lt;/STRONG&gt; -vserver cluster1&lt;BR /&gt;security login role create -role script -cmddirname "&lt;STRONG&gt;vserver options&lt;/STRONG&gt;" -access &lt;STRONG&gt;all&lt;/STRONG&gt; -query &lt;STRONG&gt;"-option-name replication.throttle.outgoing.max_kbs"&lt;/STRONG&gt; -vserver cluster1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create and apply role to a user:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;security login create -user-or-group-name &lt;STRONG&gt;jocolon&lt;/STRONG&gt; -application &lt;STRONG&gt;ontapi&lt;/STRONG&gt; -authentication-method password -role script -vserver cluster1&lt;BR /&gt;security login create -user-or-group-name &lt;STRONG&gt;jocolon&lt;/STRONG&gt; -application &lt;STRONG&gt;ssh&lt;/STRONG&gt; -authentication-method password -role script -vserver cluster1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create the powershell credential object:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;PS C:\Users\Administrator.DEMO&amp;gt; &lt;STRONG&gt;$cred = (Get-Credential)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Display powershell credential object:&lt;/STRONG&gt;&lt;BR /&gt;PS C:\Users\Administrator.DEMO&amp;gt; &lt;STRONG&gt;$cred&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;UserName Password&lt;BR /&gt;-------- --------&lt;BR /&gt;&lt;STRONG&gt;jocolon &lt;/STRONG&gt;System.Security.SecureString&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I changed your script a litter bit:&lt;/STRONG&gt;&lt;BR /&gt;PS C:\Users\Administrator.DEMO&amp;gt; Invoke-&lt;STRONG&gt;NcSsh&lt;/STRONG&gt; -Name &lt;STRONG&gt;cluster1&lt;/STRONG&gt; -Credential &lt;STRONG&gt;$cred&lt;/STRONG&gt; -Command &lt;STRONG&gt;"vserver options -option-name replication.throttle.outgoing.max_kbs 3125"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;NcController : cluster1&lt;BR /&gt;Value :&lt;/P&gt;&lt;P&gt;Last login time: 1/30/2021 15:24:50&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1 entry was modified.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Display the modified option:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;PS C:\Users\Administrator.DEMO&amp;gt; Invoke-NcSsh -Name cluster1 -Credential $cred -Command &lt;STRONG&gt;"vserver options -option-name replication.throttle.outgoing.max_kbs"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;NcController : cluster1&lt;BR /&gt;Value :&lt;/P&gt;&lt;P&gt;Last login time: 1/30/2021 15:25:06&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;cluster1&lt;BR /&gt;&lt;STRONG&gt;replication.throttle.outgoing.max_kbs 3125&lt;/STRONG&gt; -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I learn something new today! Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jan 2021 15:59:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163505#M37408</guid>
      <dc:creator>jcolonfzenpr</dc:creator>
      <dc:date>2021-01-30T15:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163543#M37412</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/81067"&gt;@jcolonfzenpr&lt;/a&gt;&amp;nbsp;. It actually works with just the following two lines:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;security login role create -role script -cmddirname "&lt;/SPAN&gt;&lt;STRONG&gt;DEFAULT&lt;/STRONG&gt;&lt;SPAN&gt;" -access&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;readonly&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;-vserver cluster1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;security login role create -role script -cmddirname "&lt;/SPAN&gt;&lt;STRONG&gt;vserver options&lt;/STRONG&gt;&lt;SPAN&gt;" -access&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;all&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;-query&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;"-option-name replication.throttle.outgoing.max_kbs"&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;-vserver cluster1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Having said that, I don't want to give even read only rights to EVERYTHING. My goal is to give only the minimal rights required, which means read only rights just to the command or command directory required to be able to log in.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 15:38:55 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163543#M37412</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2021-02-01T15:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163544#M37413</link>
      <description>&lt;P&gt;&lt;STRONG&gt;I test it also with:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;security login role create -role script -cmddirname "&lt;/SPAN&gt;&lt;STRONG&gt;DEFAULT&lt;/STRONG&gt;&lt;SPAN&gt;" -access&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;none&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;-vserver cluster1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;security login role create -role script -cmddirname "&lt;STRONG&gt;vserver&lt;/STRONG&gt;" -access&amp;nbsp;&lt;STRONG&gt;readonly&lt;/STRONG&gt;&amp;nbsp;-vserver cluster1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;security login role create -role script -cmddirname "&lt;STRONG&gt;vserver options&lt;/STRONG&gt;" -access&amp;nbsp;&lt;STRONG&gt;all&lt;/STRONG&gt;&amp;nbsp;-query&amp;nbsp;&lt;STRONG&gt;"-option-name replication.throttle.outgoing.max_kbs"&lt;/STRONG&gt;&amp;nbsp;-vserver cluster1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but you have to change a litter bit your scripts.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 15:54:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163544#M37413</guid>
      <dc:creator>jcolonfzenpr</dc:creator>
      <dc:date>2021-02-01T15:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163546#M37415</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/81067"&gt;@jcolonfzenpr&lt;/a&gt;&amp;nbsp;. I reset DEFAULT back to none and added vserver in as readonly, but that didn't work either. I do realize I had one error in the script I showed earlier.&amp;nbsp;&lt;SPAN&gt;Invoke-NaSsh should read&amp;nbsp;Invoke-NcSsh.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 16:10:32 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163546#M37415</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2021-02-01T16:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163630#M37421</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/81067"&gt;@jcolonfzenpr&lt;/a&gt;&amp;nbsp;, for the record I decided to go ahead and modify the role to make DEFAULT readonly, as this&amp;nbsp;&lt;STRONG&gt;is&lt;/STRONG&gt; at least an improvement on how it works now. It does lock it down a good bit from being a full admin to having limited rights. I have a case open with NetApp and still want to narrow this down even further to give it read only rights only to the commands needed to log in.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 16:28:17 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163630#M37421</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2021-02-02T16:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163675#M37428</link>
      <description>&lt;P&gt;If support provides a solution please share it here so other user with similar need can benefit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also i forgot to metion you can ask for help on the slack channel of netapp.io&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://join.slack.com/t/netapppub/shared_invite/zt-ki0sse86-6ihXPApFepvu0Nx~YibCtA" target="_blank"&gt;https://join.slack.com/t/netapppub/shared_invite/zt-ki0sse86-6ihXPApFepvu0Nx~YibCtA&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 13:29:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163675#M37428</guid>
      <dc:creator>jcolonfzenpr</dc:creator>
      <dc:date>2021-02-03T13:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: OnTAP Custom Role Not Working</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163676#M37429</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/81067"&gt;@jcolonfzenpr&lt;/a&gt;&amp;nbsp;I definitely will! Thanks for the tip on slack, I will check that out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a related note, I've been testing things out on the script I posted earlier in this thread. The "DEFAULT"/readonly setting + additional rule works great for this script. I've now checked out the other PowerShell scripts I want to give permission to, and forgot that I'm using native PowerShell commands for those scripts, such as&amp;nbsp;Get-NcCifsShare and Get-NcCifsShareAcl for example. At the moment it works fine since all commands are set to readonly, but if I'm able to lock "DEFAULT" down further I will need to know which NetApp commands correspond to the PowerShell commands. Do you know of a PDF that details which native NetApp commands correspond to PowerShell toolkit commands?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 13:47:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/OnTAP-Custom-Role-Not-Working/m-p/163676#M37429</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2021-02-03T13:47:12Z</dc:date>
    </item>
  </channel>
</rss>

