Secure NetApp Console
Protect storage operations by limiting NetApp Console access, securing Console agents, and monitoring activity for unauthorized or unintended changes.
Take the following steps to set up a security baseline for your organization. Follow the setup workflow for your deployment mode before you apply the security controls listed below. Learn about NetApp Console deployment modes.
Choose a NetApp Console deployment mode and complete initial setupCreate the organization and establish the first Organization admin. Complete the setup workflow that matches your deployment.
Secure Console agent permissions, network access, and hostsLimit each Console agent's cloud permissions and network access to the minimum required. Protect web-console traffic, and maintain Console agent software.
Organize the NetApp Console IAM hierarchySet up the organization hierarchy to match how your teams work. Scope storage systems, data services, and Console agents to the projects that manage them.
Configure NetApp Console identity federation and federated groupsConnect NetApp Console to your corporate identity provider (IdP) so users sign in with corporate credentials and your IdP can enforce its authentication policies. NetApp Console supports AD FS, Microsoft Entra ID, PingFederate, and generic SAML identity providers.
Add federated users and groups to the Console organization and assign them Console roles. Federation does not replace Console membership or role assignments. Learn how to add a federated group.
Add NetApp Console members and assign least-privilege rolesGive each user, service account, and federated group only the access required for its responsibilities. Assign roles at the narrowest organization, folder, or project scope that supports the work. Enable multi-factor authentication for local users.
Secure NetApp Console automation with service accountsKeep automation separate from human accounts. Assign each service account the minimum role and scope it needs. Store credentials securely and recreate them when lost or rotated.
Enable read-only mode for a NetApp Console organizationRequire administrators to elevate their role before making changes. This control reduces unintended changes to storage systems and data services.
|
|
Read-only mode is not available when NetApp Console is in private mode. |
Enforce ONTAP permissions for ONTAP System ManagerEnable Force Credentials on active Console agents that manage production ONTAP systems. Users provide their ONTAP cluster credentials when they open ONTAP System Manager, and ONTAP applies their permissions.
Review NetApp Console audit activity and security controlsEstablish a recurring review process for members, group mappings, roles, credentials, agents, and recent operations. Remove access that is no longer required and investigate unexpected activity.