The approach of have the same user/password for all arrays in a subnet seems to be the best today, despite some customers deny it due security policies.
However, the credentials of an array are also registered in DFM. Could be considered for a future release of WFA to use array credentials from DFM data?
It's true that array account used by DFM normally has restrictions to avoid operations not allowed, but like WFA account should have. I think WFA account should have CLI capabilities disabled, and only API capabilities enabled, among other considerations. DFM array account must have api + snmp + ...others. Could be merged WFA & DFM arrays accounts to be the same? maybe in oncommand core 6?
Summarizing, we're managing array credentials on two sites: Oncommand Core (DFM) and OnCommand WFA.