Skip to main content
NetApp Backup and Recovery

Set up role-based access control in NetApp Backup and Recovery

Contributors netapp-mwallis

Configure role-based access control (RBAC) in NetApp Console to control who can access NetApp Backup and Recovery resources. You can assign administrative or viewer roles to workloads that support RBAC. Workloads that do not yet support RBAC remain accessible to all users with Backup and Recovery roles until project-level or fleet-level association is available.

Note NetApp Console uses projects to organize resources within folders, while NetApp Console local deployment refers to projects as fleets.

To control access to resources in your organization, complete these steps in the Administration > Identity and access page of NetApp Console.

Note These steps assume that you are assigned the Organization admin role in NetApp Console.
Steps
  1. Create the identity and access project structure.

    As an Organization admin, set up the folder and project structure where workloads will reside.

  2. Assign user roles.

    1. Primary option:

      Add users to each project designated for workloads and grant them the appropriate role. For example:

      • Organization admin and Backup and Recovery super admin: A user with these roles can view all resources across organizations, and can discover Backup and Recovery workloads and assign them to projects (for example, US East or US West).

      • Folder or project admin and Backup and Recovery super admin: A user with these roles can view only the resources in their assigned folder or project, but can discover Backup and Recovery workloads and assign them to that project.

    2. Alternative option:

      Instead of granting a user full Backup and Recovery admin access, you can assign yourself the Backup and Recovery super admin role and discover the workloads directly.

  3. Discover workloads in Backup and Recovery.

    Organization admins or folder or project admins discover the available workloads and select the appropriate project (such as US East or US West). Each workload is automatically associated with the selected project.

  4. Add users to projects.

    Organization admins or folder or project admins add NetApp Console users to projects with workloads. Assign users the Organization viewer role and a Backup and Recovery role based on their access needs. Users with the appropriate Backup and Recovery role automatically gain access to new workloads in these projects.