Can a custom role be created that cannot control other custom roles?
Applies to
- ONTAP 9
- role-based access control (RBAC)
Answer
- When creating a custom role, it is possible to grant or restrict specific permissions for that role.
- To ensure that the custom role itself cannot be controlled, it is important not to grant administrative privileges to that role.
- Specifically, you can restrict the control of the custom role by excluding administrative privileges and permissions related to the management of other roles during the creation of the custom role.
