<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Quick start to setting up Multi-admin-verify (MAV) on labondemand.netapp.com in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Quick-start-to-setting-up-Multi-admin-verify-MAV-on-labondemand-netapp-com/m-p/467864#M45418</link>
    <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NetApp's Multi-admin-verify (MAV) is a great tool for enforcing dual control on potentially dangerous commands&amp;nbsp; (or any command - it's up to you as an admin to decide!), so having a sandbox to play with in labondemand.netapp.com was something I've long thought would be handy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, it's one thing to play in a sandbox, and another thing to make it in the first place, and know what steps to follow to set it up in your production environment. We don't have a pre-defined lab for MAV that I could find, so I wrote the attached powershell script to build one from scratch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;The script does the following:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;Creates AD OUs and groups for StorageAdmins and StorageOperators&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Provisions 9 accounts into each of them (storageadmX and storageopX), password: Netapp1!&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Creates an SVM on ONTAP cluster 1 (192.168.0.101)&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Domain joins SVM to demo.netapp.com&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Sets up domain tunnel through that SVM&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Sets up StorageAdmin and StorageOperator roles based on the admin role&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Assigns groups to roles&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Sets up MAV with StorageOperator requiring MAV approval, StorageAdmin not requiring approval&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Restricts vol delete and snap delete commands under MAV for StorageOperator&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;I’ve tested it with 9.16.1 and 9.19.1 labs and it’s done what I expected with regards to setup - I haven’t done deep testing of MAV with it, the aim is to setup an environment where MAV can be tested.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;To use it:&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;Create a lab against &lt;SPAN&gt;&lt;A title="https://labondemand.netapp.com/node/1078" href="https://labondemand.netapp.com/node/1078" target="_blank" rel="noopener"&gt;https://labondemand.netapp.com/node/1078&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;(9.16.1X) or &lt;SPAN&gt;&lt;A title="https://labondemand.netapp.com/node/1561" href="https://labondemand.netapp.com/node/1561" target="_blank" rel="noopener"&gt;https://labondemand.netapp.com/node/1561&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;(9.19.1X),&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Drag the script into the lab window once the login is finished,&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Find it in the “Cloud storage” under “My Computer”,&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Copy it to the Desktop&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Open PowerShell, and run the command&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I hope people find this helpful!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please note values are hardcoded for the demo environment on labondemand.netapp.com, but you are welcome to use it as a basis for your own environments too. This script is provided only as community supported - please do not call NetApp support for help with it.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jun 2026 03:17:51 GMT</pubDate>
    <dc:creator>AlexDawson</dc:creator>
    <dc:date>2026-06-24T03:17:51Z</dc:date>
    <item>
      <title>Quick start to setting up Multi-admin-verify (MAV) on labondemand.netapp.com</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Quick-start-to-setting-up-Multi-admin-verify-MAV-on-labondemand-netapp-com/m-p/467864#M45418</link>
      <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NetApp's Multi-admin-verify (MAV) is a great tool for enforcing dual control on potentially dangerous commands&amp;nbsp; (or any command - it's up to you as an admin to decide!), so having a sandbox to play with in labondemand.netapp.com was something I've long thought would be handy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, it's one thing to play in a sandbox, and another thing to make it in the first place, and know what steps to follow to set it up in your production environment. We don't have a pre-defined lab for MAV that I could find, so I wrote the attached powershell script to build one from scratch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;The script does the following:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;Creates AD OUs and groups for StorageAdmins and StorageOperators&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Provisions 9 accounts into each of them (storageadmX and storageopX), password: Netapp1!&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Creates an SVM on ONTAP cluster 1 (192.168.0.101)&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Domain joins SVM to demo.netapp.com&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Sets up domain tunnel through that SVM&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Sets up StorageAdmin and StorageOperator roles based on the admin role&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Assigns groups to roles&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Sets up MAV with StorageOperator requiring MAV approval, StorageAdmin not requiring approval&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Restricts vol delete and snap delete commands under MAV for StorageOperator&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;I’ve tested it with 9.16.1 and 9.19.1 labs and it’s done what I expected with regards to setup - I haven’t done deep testing of MAV with it, the aim is to setup an environment where MAV can be tested.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;To use it:&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV&gt;Create a lab against &lt;SPAN&gt;&lt;A title="https://labondemand.netapp.com/node/1078" href="https://labondemand.netapp.com/node/1078" target="_blank" rel="noopener"&gt;https://labondemand.netapp.com/node/1078&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;(9.16.1X) or &lt;SPAN&gt;&lt;A title="https://labondemand.netapp.com/node/1561" href="https://labondemand.netapp.com/node/1561" target="_blank" rel="noopener"&gt;https://labondemand.netapp.com/node/1561&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;(9.19.1X),&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Drag the script into the lab window once the login is finished,&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Find it in the “Cloud storage” under “My Computer”,&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Copy it to the Desktop&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV&gt;Open PowerShell, and run the command&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I hope people find this helpful!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please note values are hardcoded for the demo environment on labondemand.netapp.com, but you are welcome to use it as a basis for your own environments too. This script is provided only as community supported - please do not call NetApp support for help with it.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 03:17:51 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Quick-start-to-setting-up-Multi-admin-verify-MAV-on-labondemand-netapp-com/m-p/467864#M45418</guid>
      <dc:creator>AlexDawson</dc:creator>
      <dc:date>2026-06-24T03:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Quick start to setting up Multi-admin-verify (MAV) on labondemand.netapp.com</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Quick-start-to-setting-up-Multi-admin-verify-MAV-on-labondemand-netapp-com/m-p/467875#M45424</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;"Previously, we saw that the domain info had to match the creation details exactly, including case sensitivity. Has this been resolved?&lt;/DIV&gt;&lt;DIV class=""&gt;e.g.&lt;/DIV&gt;&lt;DIV class=""&gt;domain01\user01&lt;BR /&gt;or&lt;BR /&gt;Domain01\user01 (Uppercase&amp;nbsp; D)&lt;/DIV&gt;&lt;DIV class=""&gt;It did not work in 9.16.1x, and I have not tested it in 9.17.1 yet."&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 24 Jun 2026 07:55:55 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Quick-start-to-setting-up-Multi-admin-verify-MAV-on-labondemand-netapp-com/m-p/467875#M45424</guid>
      <dc:creator>a_lehn</dc:creator>
      <dc:date>2026-06-24T07:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Quick start to setting up Multi-admin-verify (MAV) on labondemand.netapp.com</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Quick-start-to-setting-up-Multi-admin-verify-MAV-on-labondemand-netapp-com/m-p/467877#M45425</link>
      <description>&lt;P&gt;Unfortunately I believe I hit that issue when developing this with 9.19 as well, so I don't think that is fixed&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 08:07:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Quick-start-to-setting-up-Multi-admin-verify-MAV-on-labondemand-netapp-com/m-p/467877#M45425</guid>
      <dc:creator>AlexDawson</dc:creator>
      <dc:date>2026-06-24T08:07:59Z</dc:date>
    </item>
  </channel>
</rss>

