NetApp ONTAP, Fujitsu ETERNUS HX/AX, Lenovo ThinkSystem DM/DG Permissions

Built-In Storage Systems

The account used to connect to NetApp ONTAP, Fujitsu ETERNUS HX/AX, Lenovo ThinkSystem DM/DG storage system must have permissions described in this section. The commands are provided for the console, UI names may differ.

Required permissions depend on what you add to the storage infrastructure. If you add a whole cluster, use the permissions listed for the cluster. If you add a storage virtual machine (SVM), use the permissions listed for the SVM.

Cluster (VMware Integration)

Cluster (VMware Integration)

Command/Directory

Access/Query Level

DEFAULT

readonly

cluster

readonly

metrocluster

readonly

vserver fcp

readonly

volume file

readonly

lun igroup

all

vserver iscsi

all

network

readonly

system node

readonly

security

readonly

security login

readonly

set

readonly

snapmirror

all

system

readonly

version

readonly

volume qtree

readonly

lun

all

vserver nfs

all

volume snapshot

all

volume

all

vserver

all

SVM (VMware Integration)

SVM (VMware Integration)

Command/Directory

Access/Query Level

DEFAULT

none

lun

all

lun igroup

all

network

readonly

security

readonly

security login

readonly

snapmirror

all

system

readonly

version

readonly

volume

all

volume file

readonly

volume qtree

all

volume snapshot

all

vserver

all

vserver fcp

all

vserver iscsi

all

vserver nfs

all

Cluster (NAS Backup Integration)

Cluster (NAS Backup Integration)

Command/Directory

Access/Query Level

DEFAULT

readonly

security

readonly

security login

readonly

volume snapshot

all

vserver

all

vserver nfs

all

snapdiff

all

Note: Required if Use native changed files tracking is enabled.

SVM (NAS Backup Integration)

SVM (NAS Backup Integration)

Command/Directory

Access/Query Level

DEFAULT

none

lun

readonly

network

readonly

security

readonly

security login

readonly

snapmirror

readonly

version

readonly

volume

readonly

volume snapshot

all

vserver

all

snapdiff

all

Note: Required if Use native changed files tracking is enabled.

Cluster (Veeam Agent Integration)

Cluster (Veeam Agent Integration)

Command/Directory

Access/Query Level

cluster

readonly

lun

all

metrocluster

readonly

network

readonly

system license

readonly

system node

readonly

version

readonly

volume

all

volume snapshot

all

vserver

all

SVM (Veeam Agent Integration)

SVM (Veeam Agent Integration)

Command/Directory

Access/Query Level

lun

all

network

readonly

version

readonly

volume

all

volume snapshot

all

vserver

all

US API Storage Systems

The account used to connect to NetApp FAS/AFF/ASA/ASA r2 storage system must have permissions described in this section. The commands are provided for the console, UI names may differ.

Basic Permissions

The following permissions are required for all integration types. These permissions are required for backup, restore, replication and snapshot workflows on both AFF/unified and ASA r2 systems. Permissions can be provided on the SVM or cluster level; otherwise it is stated in the table.

Basic Permissions

API Endpoint

Access Level

/api/cluster

readonly

/api/cluster/jobs

readonly

/api/cluster/licensing/access-tokens

read_create

/api/cluster/licensing/licenses

readonly (cluster level only)

/api/cluster/metrocluster

readonly (cluster level only)

/api/cluster/nodes

readonly (cluster level only)

/api/cluster/peers

read_create

/api/network/ip/interfaces

readonly

/api/protocols/nfs/export-policies

all

/api/protocols/nfs/services

readonly

/api/protocols/san/fcp/services

readonly

/api/protocols/san/igroups

all

/api/protocols/san/iscsi/services

readonly

/api/protocols/san/lun-maps

all

/api/snapmirror/relationships

all

/api/storage/aggregates

readonly (cluster level only)

/api/storage/luns

all

/api/storage/qtrees

all

/api/storage/snaplock/compliance-clocks

readonly

/api/storage/volumes

all

/api/svm/svms

readonly

ASA r2-Only Permissions

These permissions are required only for ASA r2 systems.

ASA r2-Only Permissions

API Endpoint

Access Level

/api/application/consistency-groups

all

/api/storage/storage-units

all


Page updated 2026-08-24

Page content applies to build 13.1.1.18