Skip to main content
NetApp Console local deployment

Add members to your NetApp Console local deployment organization

Contributors netapp-tonias netapp-ml94669

Add members to your NetApp Console local deployment organization and assign roles to grant access at the organization, folder, or fleet level for users, service accounts, and directory users.

Required access roles

Super admin, Organization admin, or Folder or fleet admin (for folders and fleets that they are administering). Learn about access roles.

Before you begin

Understand how access is granted in NetApp Console local deployment

NetApp Console uses role-based access control (RBAC) to manage permissions. Assign roles to members to provide the required access. Each role defines allowed actions for specific resources.

Note the following about granting access in NetApp Console local deployment:

  • You must explicitly add each user to your organization and assign at least one role before that user can access resources.

  • A role that you assign at the organization or folder level is inherited by child scopes, so choose the assignment scope carefully to give the member access only where needed. Learn about role inheritance in NetApp Console local deployment.

Add members to your organization

NetApp Console supports three types of members: user accounts, directory users, and service accounts.

Note You must first configure an email server to use with Console local deployment before you can add users. Learn how to configure an email server.

Directory users authenticate through your integrated directory service, but you must still add each directory user individually and assign roles in Console local deployment. Create service accounts directly in the Console.

All members must have at least one role explicitly assigned to them in order to access Console local deployment.

When adding a member, choose the organization, folder, or fleet where the member needs access and assign the starting role or roles they need.

Add a user account

You must have the Organization admin or Folder or fleet admin role to add a user to an organization, folder, or fleet so they can access resources.

Steps
  1. Select Administration > Identity and access.

  2. Select Members.

  3. Select Add a member.

  4. For Member Type, keep User selected.

  5. For User's email, enter the user's email address that is associated with the login that they created.

  6. Use the Select an organization, folder, or fleet section to choose where the member needs access.

    Note the following:

    • You can select only the folders and fleets for which you have permissions.

    • When you select an organization or folder, you grant the member permissions to all its contents.

    • You can only assign the Organization admin role at the organization level.

  7. Select a category then select a Role that gives the member the starting permissions they need for the organization, folder, or fleet you selected.

  8. To give access to more folders, fleets, or roles, select Add role, choose the folder, fleet, or role category, and select a role.

  9. Select Add.

    The Console emails instructions to the user.

Add a service account

Add a service account when you need to automate tasks or connect securely to Console APIs. After you create the account, copy its client ID and client secret for the integration that will use it.

Steps
  1. Select Administration > Identity and access.

  2. Select Members.

  3. Select Add a member.

  4. For Member Type, select Service account.

  5. Enter a name for the service account.

  6. Use the Select an organization, folder, or fleet section to choose where the service account needs access.

    Note the following:

    • You can only select from the folders and fleets for which you have permissions.

    • Selecting an organization or folder grants the member permissions to all its contents.

    • You can only assign the Organization admin role at the organization level.

  7. Select a Category then select a Role that gives the service account the starting permissions it needs for the organization, folder, or fleet you selected.

  8. To give access to more folders, fleets, or roles, select Add role, choose the folder, fleet, or role category, and select a role.

  9. Download or copy the client ID and client secret.

    The Console shows the client secret only once. Copy it securely; you can recreate it later if you lose it.

  10. Select Close.

Add a directory user to your organization

Add a user from your integrated directory service and grant their first roles. For example, add a new storage engineer from Active Directory and assign the Storage admin role on the Production-US-East fleet so they can work in that fleet.

You must first configure your directory service before you can add directory users. Learn how to integrate with your directory service.

Steps
  1. Select Administration > Identity and access.

  2. Select Members.

  3. Select Add a member.

  4. For Member Type, select Directory user.

  5. For User's email, enter the email address of the directory user that you want to add. This email address must match the email address associated with the user's login in your directory.

  6. Use the Select an organization, folder, or fleet section to choose where the directory user needs access.

    Note the following:

    • You can only select from the folders and fleets for which you have permissions.

    • Selecting an organization or folder grants the member permissions to all its contents.

    • You can only assign the Organization admin role at the organization level.

  7. Select a Category then select a Role that gives the directory user the starting permissions they need for the organization, folder, or fleet you selected.

  8. To give the user additional access to other folders, fleets, or roles, select Add role, choose the folder or fleet, role category, and select a role.