<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ontap gui login with diffent active directory domains in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Ontap-gui-login-with-diffent-active-directory-domains/m-p/463079#M45149</link>
    <description>&lt;P&gt;I am pretty sure this will not work in your case...Much of the GUI is REST-related and this trick does not work with REST:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when creating RBAC, many forget about the -query option.&lt;/P&gt;&lt;PRE&gt;security login role create -role corpAAA_admin -cmddirname volume -query "-vserver svm_AAA" -access all&lt;/PRE&gt;&lt;P&gt;Basically, you have a couple choices:&lt;/P&gt;&lt;P&gt;1. you can give the admins ability to "login" to their own SVM, but they will be limited to CLI access.&lt;/P&gt;&lt;P&gt;2. you can give the admins ability t "login" to the main cluster, but you define EVERY command they can run and be very judicious with the "-query" option which will limit the user to only run things in their own SVM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would love to be proven wrong, but as far as I know there is no way to "limit" GUI access to an SVM.&lt;/P&gt;&lt;P&gt;It is a catch 22... You can specify "rest-role" but they are targeted to a data svm. the GUI is the admin svm.&lt;/P&gt;&lt;P&gt;If I provide access to the GUI, I need to find a way to limit (which again, I do not think is possible)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully this is a bit clearer than mud.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Sep 2025 15:49:33 GMT</pubDate>
    <dc:creator>TMACMD</dc:creator>
    <dc:date>2025-09-10T15:49:33Z</dc:date>
    <item>
      <title>Ontap gui login with diffent active directory domains</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Ontap-gui-login-with-diffent-active-directory-domains/m-p/463078#M45148</link>
      <description>&lt;P&gt;Hello to all&amp;nbsp;&lt;/P&gt;&lt;P&gt;We got a customer with 3 diferent Active Directory&amp;nbsp; domains, for example AAA.corp,BBB.corp and CCC.corp.&lt;/P&gt;&lt;P&gt;we had created 3 different SVM in ontap 9.16 and created volumes and shares. Everything is fine.&lt;/P&gt;&lt;P&gt;when i want&amp;nbsp;to let domain admins logon to GUI&amp;nbsp; of&amp;nbsp; netapp (system manager) with domain admin accounts , but not reaching anything else then their own SVM ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;yet we couldnt do it,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can logon with ActiveDirectory accounts when we let permission with Cluster SVM ,but then can reach everything&lt;/P&gt;&lt;P&gt;created RBAC role, and assigned role to users ,then we can logon but that time, can reach all SVM systems&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what can you advise&amp;nbsp; to do,?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 15:19:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Ontap-gui-login-with-diffent-active-directory-domains/m-p/463078#M45148</guid>
      <dc:creator>ORCUN_USTURALI</dc:creator>
      <dc:date>2025-09-10T15:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: Ontap gui login with diffent active directory domains</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Ontap-gui-login-with-diffent-active-directory-domains/m-p/463079#M45149</link>
      <description>&lt;P&gt;I am pretty sure this will not work in your case...Much of the GUI is REST-related and this trick does not work with REST:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when creating RBAC, many forget about the -query option.&lt;/P&gt;&lt;PRE&gt;security login role create -role corpAAA_admin -cmddirname volume -query "-vserver svm_AAA" -access all&lt;/PRE&gt;&lt;P&gt;Basically, you have a couple choices:&lt;/P&gt;&lt;P&gt;1. you can give the admins ability to "login" to their own SVM, but they will be limited to CLI access.&lt;/P&gt;&lt;P&gt;2. you can give the admins ability t "login" to the main cluster, but you define EVERY command they can run and be very judicious with the "-query" option which will limit the user to only run things in their own SVM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would love to be proven wrong, but as far as I know there is no way to "limit" GUI access to an SVM.&lt;/P&gt;&lt;P&gt;It is a catch 22... You can specify "rest-role" but they are targeted to a data svm. the GUI is the admin svm.&lt;/P&gt;&lt;P&gt;If I provide access to the GUI, I need to find a way to limit (which again, I do not think is possible)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully this is a bit clearer than mud.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 15:49:33 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Ontap-gui-login-with-diffent-active-directory-domains/m-p/463079#M45149</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2025-09-10T15:49:33Z</dc:date>
    </item>
  </channel>
</rss>

