<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Role with no permissions to delete Snapshots using System Manager in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433571#M40356</link>
    <description>&lt;P&gt;Have you checked this:&lt;BR /&gt;&lt;A title="FAQ:  Custom roles for administration of ONTAP" href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/FAQ%3A__Custom_roles_for_administration_of_ONTAP" target="_blank" rel="noopener"&gt;FAQ: Custom roles for administration of ONTAP&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also did you verify that you logged in with the user that doesn't have permission? How did you manage to set the role for that user?&lt;/P&gt;</description>
    <pubDate>Fri, 01 Apr 2022 05:14:58 GMT</pubDate>
    <dc:creator>tahmad</dc:creator>
    <dc:date>2022-04-01T05:14:58Z</dc:date>
    <item>
      <title>Custom Role with no permissions to delete Snapshots using System Manager</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433531#M40349</link>
      <description>&lt;P&gt;We would like to have a custom admin role which is allowed for everything except of deleting snapshots. We could successfully create a custom role and assigned a testuser to this role.&lt;/P&gt;&lt;P&gt;The permissions seems to work, when connected via SSH to the CLI, the testuser can not delete snapshots. But when using the System Manager, the testuser is still allowed to delete snapshots.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the custom admin role looks like that:&lt;BR /&gt;Role Command/ Access Vserver Name Directory Query Level&lt;BR /&gt;---------- ------------- --------- ----------------------------------- --------&lt;BR /&gt;vserver admin_custom DEFAULT all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; volume snapshot delete none&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea why the behaviour in GUI and CLI is different? Does the role need different permissions for working correctly in GUI?&lt;/P&gt;&lt;P&gt;Thank you for any suggestions&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:02:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433531#M40349</guid>
      <dc:creator>esolva</dc:creator>
      <dc:date>2025-06-04T10:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Role with no permissions to delete Snapshots using System Manager</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433571#M40356</link>
      <description>&lt;P&gt;Have you checked this:&lt;BR /&gt;&lt;A title="FAQ:  Custom roles for administration of ONTAP" href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/FAQ%3A__Custom_roles_for_administration_of_ONTAP" target="_blank" rel="noopener"&gt;FAQ: Custom roles for administration of ONTAP&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also did you verify that you logged in with the user that doesn't have permission? How did you manage to set the role for that user?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 05:14:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433571#M40356</guid>
      <dc:creator>tahmad</dc:creator>
      <dc:date>2022-04-01T05:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Role with no permissions to delete Snapshots using System Manager</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433574#M40357</link>
      <description>&lt;P&gt;Thank you for your reply, yes I've already checked that FAQ.&lt;/P&gt;&lt;P&gt;User was created and set to this role with the following command:&lt;BR /&gt;security login create -user-or-group-name testuser -application http -authmethod password -role admin_custom -vserver vserver&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did another test setting the volume snapshot permission to read only for that role:&lt;BR /&gt;security login role create -role admin_customer -cmddirname "volume snapshot" -access readonly -vserver vserver&lt;/P&gt;&lt;P&gt;This works like expected, the user is not allowed to delete snapshot but also creating or modifying snapshot is prohibited. We do like that snapshot creation is allowed and only deletion is not allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 05:28:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433574#M40357</guid>
      <dc:creator>esolva</dc:creator>
      <dc:date>2022-04-01T05:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Role with no permissions to delete Snapshots using System Manager</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433575#M40358</link>
      <description>&lt;P&gt;Actually this KB should do the job:&lt;/P&gt;&lt;P&gt;&lt;A title="How to use RBAC to prevent deletion of snapshots and volumes" href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_use_RBAC_to_prevent_deletion_of_snapshots_and_volumes" target="_blank" rel="noopener"&gt;How to use RBAC to prevent deletion of snapshots and volumes&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly let me know if it works&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 06:25:20 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433575#M40358</guid>
      <dc:creator>tahmad</dc:creator>
      <dc:date>2022-04-01T06:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Role with no permissions to delete Snapshots using System Manager</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433596#M40362</link>
      <description>&lt;P&gt;this is exactly what I tried first, but unfortunately this works only in CLI.&amp;nbsp; when using GUI still i'm still able to delete snapshots&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 14:27:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433596#M40362</guid>
      <dc:creator>esolva</dc:creator>
      <dc:date>2022-04-01T14:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Role with no permissions to delete Snapshots using System Manager</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433619#M40363</link>
      <description>&lt;P&gt;In the upper right corner of System Manager is two characters "&amp;lt; &amp;gt;" (greater than and less than). Click that and see what kind of API call System Manager is doing. That might provide a clue. Also reference the audit log. If it looks right, you may have to open a case so we can file a bug.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 22:15:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Custom-Role-with-no-permissions-to-delete-Snapshots-using-System-Manager/m-p/433619#M40363</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2022-04-01T22:15:44Z</dc:date>
    </item>
  </channel>
</rss>

