<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Virtual Storage Console Limited Use Rights in VMware Solutions Discussions</title>
    <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/Virtual-Storage-Console-Limited-Use-Rights/m-p/164445#M9802</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am attempting to reduce rights to the bare minimum on local OnTAP service accounts to increase our security posture. I've created a custom role for the VSC service account that just allows for discovery, however it occurred to me that we can probably go further.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use VSC for &lt;STRONG&gt;one single purpose&lt;/STRONG&gt; only: to verify our ESX host settings match NetApp best practices. The only thing we do is browse to&amp;nbsp;&lt;STRONG&gt;Overview&lt;/STRONG&gt; and click&amp;nbsp;&lt;STRONG&gt;Edit ESXi Host Settings&lt;/STRONG&gt; when we have a new ESX host added. With this in mind: do we need an account on the cluster at all? Do we have to perform discovery if all we do is apply appropriate settings to ESX hosts? In other words: do I even need a local service account at all? Would love to hear any suggestions or thoughts!&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 10:33:30 GMT</pubDate>
    <dc:creator>TMADOCTHOMAS</dc:creator>
    <dc:date>2025-06-04T10:33:30Z</dc:date>
    <item>
      <title>Virtual Storage Console Limited Use Rights</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/Virtual-Storage-Console-Limited-Use-Rights/m-p/164445#M9802</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am attempting to reduce rights to the bare minimum on local OnTAP service accounts to increase our security posture. I've created a custom role for the VSC service account that just allows for discovery, however it occurred to me that we can probably go further.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use VSC for &lt;STRONG&gt;one single purpose&lt;/STRONG&gt; only: to verify our ESX host settings match NetApp best practices. The only thing we do is browse to&amp;nbsp;&lt;STRONG&gt;Overview&lt;/STRONG&gt; and click&amp;nbsp;&lt;STRONG&gt;Edit ESXi Host Settings&lt;/STRONG&gt; when we have a new ESX host added. With this in mind: do we need an account on the cluster at all? Do we have to perform discovery if all we do is apply appropriate settings to ESX hosts? In other words: do I even need a local service account at all? Would love to hear any suggestions or thoughts!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:33:30 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/Virtual-Storage-Console-Limited-Use-Rights/m-p/164445#M9802</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2025-06-04T10:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Storage Console Limited Use Rights</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/Virtual-Storage-Console-Limited-Use-Rights/m-p/164481#M9803</link>
      <description>&lt;P&gt;If the ONLY thing you want is the ESXi host settings, have you considered using a PowerCLI script to check/implement the settings?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are documented here:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.netapp.com/vapp-97/topic/com.netapp.doc.vsc-dsg/GUID-346ACB95-6AD4-4DEA-8901-C9697AC3530F.html#GUID-346ACB95-6AD4-4DEA-8901-C9697AC3530F" target="_blank"&gt;https://docs.netapp.com/vapp-97/topic/com.netapp.doc.vsc-dsg/GUID-346ACB95-6AD4-4DEA-8901-C9697AC3530F.html#GUID-346ACB95-6AD4-4DEA-8901-C9697AC3530F&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 16:45:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/Virtual-Storage-Console-Limited-Use-Rights/m-p/164481#M9803</guid>
      <dc:creator>JohnChampion</dc:creator>
      <dc:date>2021-02-26T16:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Storage Console Limited Use Rights</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/Virtual-Storage-Console-Limited-Use-Rights/m-p/164484#M9804</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/37407"&gt;@JohnChampion&lt;/a&gt;&amp;nbsp;! I have seen that list before, but never thought about scripting the changes in PowerShell. I don't know that I will have time to write and troubleshoot a PS script for something like that however. Plus I really like being able to look in VSC and verify that settings are correct for all systems.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 18:04:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/Virtual-Storage-Console-Limited-Use-Rights/m-p/164484#M9804</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2021-02-26T18:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual Storage Console Limited Use Rights</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/Virtual-Storage-Console-Limited-Use-Rights/m-p/164677#M9808</link>
      <description>&lt;P&gt;Bumping this to see if anyone is able to answer my question regarding whether I need a VSC local account on the NetApp at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a correlary question: if I do need to keep it, I've already given the account a custom role based on documented limited rights the account needs. However, some of those rights are still admin-oriented, which still leaves me a little concerned about someone gaining access to the account. The only application applied to the account is&amp;nbsp;&lt;STRONG&gt;ontapi&lt;/STRONG&gt;. I am not clear about what "ontapi" really means in this context. If someone obtained access to the account, what would they be able to do with the "ontapi" application?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 19:44:38 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/Virtual-Storage-Console-Limited-Use-Rights/m-p/164677#M9808</guid>
      <dc:creator>TMADOCTHOMAS</dc:creator>
      <dc:date>2021-03-05T19:44:38Z</dc:date>
    </item>
  </channel>
</rss>

