<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Domain account sometimes denied access in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Domain-account-sometimes-denied-access/m-p/28300#M5902</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm running OnCommand Operations manager 5.0 on a dedicated server.&amp;nbsp; I have the OnCommand host service running as a domain account, and in OnCommand, I am having it connect to all of my controllers using a domain account.&amp;nbsp; This domain account is in the Administrators group on all filers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, since I set this up, I see many errors denying access to my domain account in the messages logs on all my controllers.&amp;nbsp; OnCommand appears to function, so it's getting partial access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the message I get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User 'MyDomain\MyDomainAccount' denied access - missing required capability: 'api-perf-object-get-instances'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've verified the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I can connect to the controller via SSH using this domain acount.&amp;nbsp; I run the stats list instances system with success.&lt;/P&gt;&lt;P&gt;- I can connect via HTTP/HTTPS using powershell with the domain credentials (Using Powershell):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Connect-NaController ctrl1 -HTTPS -Credential (Get-Credential)&lt;/P&gt;&lt;P&gt;Get-NaPerfInstance system&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp; I can connect to the controller using OnCommand System Manager 2.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The domain user has Administrator access, which includes the admin role, which has the api-* capability.&amp;nbsp; I can't figure out why I'm getting any access denied messages at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jun 2025 06:41:33 GMT</pubDate>
    <dc:creator>bsti</dc:creator>
    <dc:date>2025-06-05T06:41:33Z</dc:date>
    <item>
      <title>Domain account sometimes denied access</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Domain-account-sometimes-denied-access/m-p/28300#M5902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm running OnCommand Operations manager 5.0 on a dedicated server.&amp;nbsp; I have the OnCommand host service running as a domain account, and in OnCommand, I am having it connect to all of my controllers using a domain account.&amp;nbsp; This domain account is in the Administrators group on all filers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, since I set this up, I see many errors denying access to my domain account in the messages logs on all my controllers.&amp;nbsp; OnCommand appears to function, so it's getting partial access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the message I get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User 'MyDomain\MyDomainAccount' denied access - missing required capability: 'api-perf-object-get-instances'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've verified the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I can connect to the controller via SSH using this domain acount.&amp;nbsp; I run the stats list instances system with success.&lt;/P&gt;&lt;P&gt;- I can connect via HTTP/HTTPS using powershell with the domain credentials (Using Powershell):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Connect-NaController ctrl1 -HTTPS -Credential (Get-Credential)&lt;/P&gt;&lt;P&gt;Get-NaPerfInstance system&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp; I can connect to the controller using OnCommand System Manager 2.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The domain user has Administrator access, which includes the admin role, which has the api-* capability.&amp;nbsp; I can't figure out why I'm getting any access denied messages at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:41:33 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Domain-account-sometimes-denied-access/m-p/28300#M5902</guid>
      <dc:creator>bsti</dc:creator>
      <dc:date>2025-06-05T06:41:33Z</dc:date>
    </item>
    <item>
      <title>Domain account sometimes denied access</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Domain-account-sometimes-denied-access/m-p/28304#M5903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I got an answer to this on the NetApp forums.&amp;nbsp; It's apparently a bug:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://now.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=310141" target="_blank"&gt;http://now.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=310141&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 02:54:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Domain-account-sometimes-denied-access/m-p/28304#M5903</guid>
      <dc:creator>bsti</dc:creator>
      <dc:date>2011-11-11T02:54:35Z</dc:date>
    </item>
  </channel>
</rss>

