<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ONTAP Tools for VMware vSphere - service account permissions in VMware Solutions Discussions</title>
    <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453886#M10055</link>
    <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/12714"&gt;@ChanceBingen&lt;/a&gt;&amp;nbsp;- ty sir, appreciate it. We're going to try it out in our test/engineering labs&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2024 20:40:30 GMT</pubDate>
    <dc:creator>prcpa8w3p</dc:creator>
    <dc:date>2024-07-10T20:40:30Z</dc:date>
    <item>
      <title>ONTAP Tools for VMware vSphere - service account permissions</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453266#M10037</link>
      <description>&lt;P&gt;Setting up OTV using a service account and per our internal security team best practices, they won't allow us to give the service account administrator rights into vCenter.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are the granular permissions that we can grant to the service account that'll still allow us to both successfully install and manage OTV?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Configuration:&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;vCenter: 8.0 Update 2&lt;/P&gt;&lt;P&gt;ONTAP: 9.13.1Px&lt;/P&gt;&lt;P&gt;OTV: 9.13P1&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 16:27:16 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453266#M10037</guid>
      <dc:creator>prcpa8w3p</dc:creator>
      <dc:date>2024-06-18T16:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP Tools for VMware vSphere - service account permissions</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453477#M10039</link>
      <description>&lt;P&gt;Hi All - any update on this?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 14:49:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453477#M10039</guid>
      <dc:creator>prcpa8w3p</dc:creator>
      <dc:date>2024-06-25T14:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP Tools for VMware vSphere - service account permissions</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453516#M10040</link>
      <description>&lt;P&gt;I haven't tried, but according to this two key things you need are access to the&amp;nbsp;&lt;SPAN class=""&gt;ExtensionManager.registerExtension()&lt;/SPAN&gt;&lt;SPAN&gt;, updateExtension(), and I'm also guessing you will want to have access to the&amp;nbsp;unregisterExtension() methods collectively.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-eam-developer-guide/GUID-2A14C632-F90E-42C9-A17F-2ED8BAD0C5B2.html" target="_blank" rel="noopener"&gt;Connect the extension to vCenter Server (vmware.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-eam-developer-guide/GUID-E0F50391-5079-435F-ADA7-7E3311900234.html" target="_blank" rel="noopener"&gt;Unregister the extension from vCenter Server (vmware.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you register the plugin, it also creates roles so you need to have rights to do that too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you actually use the product, it operates as the logged in user. So creating datastores and such are inherited from that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I look in the vCenter GUI, I can see these. Give it a try and let us know how it goes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChanceBingen_0-1719424324069.png" style="width: 711px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/28518i9E76D83A68603BBC/image-dimensions/711x546?v=v2" width="711" height="546" role="button" title="ChanceBingen_0-1719424324069.png" alt="ChanceBingen_0-1719424324069.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 17:54:51 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453516#M10040</guid>
      <dc:creator>ChanceBingen</dc:creator>
      <dc:date>2024-06-26T17:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP Tools for VMware vSphere - service account permissions</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453517#M10041</link>
      <description>&lt;P&gt;Also, this KB may do the trick too.&amp;nbsp;&lt;A href="https://kb.netapp.com/data-mgmt/OTV/SRA_Kbs/How_to_create_a_service_account_in_vCenter_for_only_allowing_VSC_SRM_Functions" target="_blank"&gt;How to create a service account in vCenter for only allowing VSC/SRM Functions - NetApp Knowledge Base&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 17:57:54 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453517#M10041</guid>
      <dc:creator>ChanceBingen</dc:creator>
      <dc:date>2024-06-26T17:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP Tools for VMware vSphere - service account permissions</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453874#M10053</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/12714"&gt;@ChanceBingen&lt;/a&gt;&amp;nbsp; - thank you for looking into this. We keep coming across the following NetApp KBA which we don't currently have access to - is it possible for you to share the contents?&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/Virtual_Storage_Console_for_VMware_vSphere/How_to_configure_RBAC_for_Virtual_Storage_Console" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/Virtual_Storage_Console_for_VMware_vSphere/How_to_configure_RBAC_for_Virtual_Storage_Console&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 15:28:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453874#M10053</guid>
      <dc:creator>prcpa8w3p</dc:creator>
      <dc:date>2024-07-10T15:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP Tools for VMware vSphere - service account permissions</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453882#M10054</link>
      <description>&lt;P&gt;Looks like that KB has been archived and replaced with this one:&amp;nbsp;&lt;A href="https://kb.netapp.com/data-mgmt/OTV/VSC_Kbs/VSC_VASA_and_SRA_ONTAP_RBAC_Configuration" target="_blank"&gt;ONTAP Tools for VMware vSphere: RBAC Configuration - NetApp Knowledge Base&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 17:49:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453882#M10054</guid>
      <dc:creator>ChanceBingen</dc:creator>
      <dc:date>2024-07-10T17:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP Tools for VMware vSphere - service account permissions</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453886#M10055</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/12714"&gt;@ChanceBingen&lt;/a&gt;&amp;nbsp;- ty sir, appreciate it. We're going to try it out in our test/engineering labs&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 20:40:30 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/ONTAP-Tools-for-VMware-vSphere-service-account-permissions/m-p/453886#M10055</guid>
      <dc:creator>prcpa8w3p</dc:creator>
      <dc:date>2024-07-10T20:40:30Z</dc:date>
    </item>
  </channel>
</rss>

