<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2FA/MFA MAV securities and AIQ/WFA accounts in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/2FA-MFA-MAV-securities-and-AIQ-WFA-accounts/m-p/441330#M41718</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a little question, in case I missed something...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are securing our admin accesses to Netapp Clusters using 2FA (password + sshKey) and thinking about deploying MAV (Multi Admin Validation) !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But how to handle admin accounts used by ActiveIQ and WorflowAutomation ? AFAIK there is no way to restrict the IP address used by a specific login ?!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;GS.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 09:53:19 GMT</pubDate>
    <dc:creator>StockageUGA</dc:creator>
    <dc:date>2025-06-04T09:53:19Z</dc:date>
    <item>
      <title>2FA/MFA MAV securities and AIQ/WFA accounts</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/2FA-MFA-MAV-securities-and-AIQ-WFA-accounts/m-p/441330#M41718</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a little question, in case I missed something...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are securing our admin accesses to Netapp Clusters using 2FA (password + sshKey) and thinking about deploying MAV (Multi Admin Validation) !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But how to handle admin accounts used by ActiveIQ and WorflowAutomation ? AFAIK there is no way to restrict the IP address used by a specific login ?!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;GS.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:53:19 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/2FA-MFA-MAV-securities-and-AIQ-WFA-accounts/m-p/441330#M41718</guid>
      <dc:creator>StockageUGA</dc:creator>
      <dc:date>2025-06-04T09:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA/MFA MAV securities and AIQ/WFA accounts</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/2FA-MFA-MAV-securities-and-AIQ-WFA-accounts/m-p/441331#M41719</link>
      <description>&lt;P&gt;Please check the following pdf.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enabling SAML authentication for System Manager &amp;amp; Active IQ Unified Manager:&lt;BR /&gt;&lt;A href="https://www.netapp.com/pdf.html?item=/media/17055-tr4647.pdf" target="_blank"&gt;https://www.netapp.com/pdf.html?item=/media/17055-tr4647.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/task_security_mfa_setup.html#enable-saml-authentication" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/task_security_mfa_setup.html#enable-saml-authentication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 11:29:41 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/2FA-MFA-MAV-securities-and-AIQ-WFA-accounts/m-p/441331#M41719</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2023-01-31T11:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA/MFA MAV securities and AIQ/WFA accounts</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/2FA-MFA-MAV-securities-and-AIQ-WFA-accounts/m-p/441333#M41720</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, but the PDF is not completely answering my question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;eg: Netapp Workflow Automation needs privileged credentials on clusters to create volumes/vservers etc... It seems that It only supports Login/Password based credentials.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;eg2: Netapp Active IQ Unified Manager needs admin credentials on clusters to interact with them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you have to keep an admin account on your cluster only protected by (strong) password !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In TR4647, there is a note about it page 53&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After SAML authentication is configured for the http and ontapi applications, the password&lt;BR /&gt;authentication method does not need to be configured. They remain configured for administrator&lt;BR /&gt;accounts to enable external supportability tools to continue administrator access with single-factor&lt;BR /&gt;user ID/password authentication. If no such tools require user ID/password access, delete all&lt;BR /&gt;password authentication methods for all administrator accounts for http and ontapi&lt;BR /&gt;applications to provide the most secure administrative access environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;GS&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 13:37:48 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/2FA-MFA-MAV-securities-and-AIQ-WFA-accounts/m-p/441333#M41720</guid>
      <dc:creator>StockageUGA</dc:creator>
      <dc:date>2023-01-31T13:37:48Z</dc:date>
    </item>
  </channel>
</rss>

