<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom role required with access to only few SVMs in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Custom-role-required-with-access-to-only-few-SVMs/m-p/170677#M39257</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;hmoubara,&lt;/P&gt;&lt;P&gt;I've seen this FAQ but it does not cover what I need - the crux of the question is how a cluster custom role can grant selective permissions in only selected SVMs&amp;nbsp; as above...&lt;/P&gt;</description>
    <pubDate>Fri, 08 Oct 2021 08:04:17 GMT</pubDate>
    <dc:creator>ppadmgeo1</dc:creator>
    <dc:date>2021-10-08T08:04:17Z</dc:date>
    <item>
      <title>Custom role required with access to only few SVMs</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Custom-role-required-with-access-to-only-few-SVMs/m-p/170642#M39254</link>
      <description>&lt;P&gt;I need to create a custom role that allows a group of administrators from AD_domain_A to manage all bar one PCI DSS SVM. That last PCI DSS SVM is joined to another domain (AD_domain_B) and will be managed via SSH directly to the SVM admin lif as I understand that ONTAP System Manager is only available on cluster level.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried creating a custom role AD_Admin as attached on cluster level which grants access to the&amp;nbsp;group of administrators from AD_domain_A, I then added that same AD group to vsadmin role within the non-PCI SVMs but the resulting access is not&amp;nbsp;AD_Admin +&amp;nbsp;vsadmin. I think I possibly incorrectly assumed that the permissions will be additive and ad admins can't resize volumes etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the best way to setup this role? Do I need to add, as part of the&amp;nbsp;AD_Admin role definition, something like this but that would mean listing all commands and repeating this for all SVMs?&lt;/P&gt;&lt;P&gt;security login role create -role AD_Admin -cmddirname "volume modify" -access all -query "-vserver svm1"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:11:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Custom-role-required-with-access-to-only-few-SVMs/m-p/170642#M39254</guid>
      <dc:creator>ppadmgeo1</dc:creator>
      <dc:date>2025-06-04T10:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: Custom role required with access to only few SVMs</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Custom-role-required-with-access-to-only-few-SVMs/m-p/170646#M39255</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the below kb:&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/FAQ%3A__Custom_roles_for_administration_of_ONTAP" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/FAQ%3A__Custom_roles_for_administration_of_ONTAP&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps answer your question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 01:56:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Custom-role-required-with-access-to-only-few-SVMs/m-p/170646#M39255</guid>
      <dc:creator>hmoubara</dc:creator>
      <dc:date>2021-10-08T01:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: Custom role required with access to only few SVMs</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Custom-role-required-with-access-to-only-few-SVMs/m-p/170677#M39257</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;hmoubara,&lt;/P&gt;&lt;P&gt;I've seen this FAQ but it does not cover what I need - the crux of the question is how a cluster custom role can grant selective permissions in only selected SVMs&amp;nbsp; as above...&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 08:04:17 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Custom-role-required-with-access-to-only-few-SVMs/m-p/170677#M39257</guid>
      <dc:creator>ppadmgeo1</dc:creator>
      <dc:date>2021-10-08T08:04:17Z</dc:date>
    </item>
  </channel>
</rss>

