Skip to main content
NetApp Console setup and administration

Secure NetApp Console

Contributors netapp-tonias

Protect storage operations by limiting NetApp Console access, securing Console agents, and monitoring activity for unauthorized or unintended changes.

Take the following steps to set up a security baseline for your organization. Follow the setup workflow for your deployment mode before you apply the security controls listed below. Learn about NetApp Console deployment modes.

One Choose a NetApp Console deployment mode and complete initial setup

Create the organization and establish the first Organization admin. Complete the setup workflow that matches your deployment.

Two Secure Console agent permissions, network access, and hosts

Limit each Console agent's cloud permissions and network access to the minimum required. Protect web-console traffic, and maintain Console agent software.

Three Organize the NetApp Console IAM hierarchy

Set up the organization hierarchy to match how your teams work. Scope storage systems, data services, and Console agents to the projects that manage them.

Four Configure NetApp Console identity federation and federated groups

Connect NetApp Console to your corporate identity provider (IdP) so users sign in with corporate credentials and your IdP can enforce its authentication policies. NetApp Console supports AD FS, Microsoft Entra ID, PingFederate, and generic SAML identity providers.

Add federated users and groups to the Console organization and assign them Console roles. Federation does not replace Console membership or role assignments. Learn how to add a federated group.

Five Add NetApp Console members and assign least-privilege roles

Give each user, service account, and federated group only the access required for its responsibilities. Assign roles at the narrowest organization, folder, or project scope that supports the work. Enable multi-factor authentication for local users.

Six Secure NetApp Console automation with service accounts

Keep automation separate from human accounts. Assign each service account the minimum role and scope it needs. Store credentials securely and recreate them when lost or rotated.

Seven Enable read-only mode for a NetApp Console organization

Require administrators to elevate their role before making changes. This control reduces unintended changes to storage systems and data services.

Note Read-only mode is not available when NetApp Console is in private mode.
Eight Enforce ONTAP permissions for ONTAP System Manager

Enable Force Credentials on active Console agents that manage production ONTAP systems. Users provide their ONTAP cluster credentials when they open ONTAP System Manager, and ONTAP applies their permissions.

Nine Review NetApp Console audit activity and security controls

Establish a recurring review process for members, group mappings, roles, credentials, agents, and recent operations. Remove access that is no longer required and investigate unexpected activity.