ONTAP Discussions

Multi-admin Verify support for ADS groups

a_lehn
18,222 Views

Hi
We are currently testing the use of MAV which is supported in Ontap 9.11.1x.

As I see it, it is only possible to create local users as approvers, does anyone know if there will be support for using AD groups as  a approvers. ?


The idea is via. automation that a user is temporarily members of a AD group to approve pending approver

1 ACCEPTED SOLUTION

elementx
18,139 Views

Do you need one of the two accounts to be ADS-based and the other local based, or both ADS-based?

If you want the both to be ADS-based, how do you plan to handle ADS outage or unplanned downtime?

View solution in original post

27 REPLIES 27

DaveNorrie
12,543 Views

Adding my +1 too. This would be much easier to manage than individual AD users.

AlexDawson
78 Views

For reference of anyone viewing this thread in the future - Active Directory group support for MAV approval groups was added in 9.15.1 - https://docs.netapp.com/us-en/ontap/multi-admin-verify/manage-groups-task.html#system-manager-procedure

"Isn't what we are experiencing in 9.17.1x also that if we use AD groups (admin role), you still cannot do approvals between users who are members of the same AD group?
If you assign the admin role to AD users domain\userid01 and domain\userid02 directly, it works across userid01 <-> userid02." and local Ontap users
 

 

AlexDawson
52 Views

Can I ask you to setup a labondemand with MAV following my guide and script at https://community.netapp.com/t5/ONTAP-Discussions/Quick-start-to-setting-up-Multi-admin-verify-MAV-on-labondemand-netapp-com/m-p/467864 and let me know how it goes? Thanks!

@AlexDawson Hi and thank you, but...

that doc article describes how to use ist with DOMAIN\USERS (and USERS only).

we have 9.16.1p12 installed and to create a MFA-group with a domain\GROUP is still not possible.

1Screenshot 2026-06-24 084952.png

"Error: command failed: Approval groups need valid users." (screenshot attached)
nice regards reinhard

Hi! Can I ask you to setup a labondemand with MAV following my guide and script at https://community.netapp.com/t5/ONTAP-Discussions/Quick-start-to-setting-up-Multi-admin-verify-MAV-on-labondemand-netapp-com/m-p/467864 and let me know how it goes? This lets you test against a known good configuration and may help with troubleshooting further

Hi Alex,

that script helped.

my error was, you need to create a new "security login create" for that specific group:

2Screenshot 2026-06-24 103424.png

it does not help that that group is part of the AD, it needs to be "inserted" into ontap.

nice regards and thank you

Reinhard

Public