Active IQ Unified Manager Discussions

Restrict "Domain Admins" in Operations Manager

pius_gaehwiler
3,437 Views

Hi,

 

our Netapp filers are integrated in our AD domain and also DFM is installed on a MemberServer of this Domain. With this setup the members of Domain Admins has full access to the Operations Manager (DFM) regardless of the RBAC settings 😞  RBAC is working fine for not Domain Admins, Windows domain admins are not netapp experts, and therewith they shouldn't have full access.

 

Is there any solution to restict Domain Admins?

 

 

Cheers,

 

Pius

3 REPLIES 3

eduard_abrahamyan
3,437 Views

Hi

We have same issue. Due the DFM installed on a server whish is member of a domain the all domain users have full access rights to DFM.

Need to restrict acess.

There is everyone without roles, how can we remove the everyone account from DFM?

thanks.

Eduard Abrahamyan

eduard_abrahamyan
3,437 Views

by default Windows Administrators group members are super-users in DFM.

Is it possible to change it to other group or restrict the rights level for buildin\Administrators group.

DAMIANGILL
3,437 Views

I have tried to get this looked at, contacting different partner resources but no joy

My post was made here https://communities.netapp.com/thread/33728

Would be great to get this changed so rather than the local administrators group being used (which has Domain Admins nested within it) you could simply just pick a specific AD group.

Come on NetApp!!

Public