Skip to main content

ONTAP administrator authentication and RBAC workflow summary

Contributors netapp-bhouser netapp-mwallis netapp-aherbin netapp-thomi

You can enable authentication for local administrator accounts or remote administrator accounts. The account information for a local account resides on the storage system and the account information for a remote account resides elsewhere. Each account can have a predefined role or a custom role.

OneComplete configuration worksheet

Before creating login accounts and setting up role-based access control (RBAC), you should gather information for each item in the configuration worksheets.

TwoDetermine if the administrator account is local or remote
ThreeSet up role-based access

The role assigned to an administrator determines the commands to which the administrator has access. The role is assigned when you create the administrator account and can be modified later. You can use predefined roles for cluster and SVM administrators, or define custom roles as needed.

FourManage administrator accounts

Depending on how you have enabled account access, you may need to associate a public key with a local account, manage public keys and X.509 certificates, configure Cisco Duo 2FA for SSH logins, install a CA-signed server digital certificate, or configure Active Directory, LDAP, or NIS access. You can perform all of these tasks before or after enabling account access.

FiveConfigure additional security features