Creating a View-Only Administrator Role in Nutanix Prism Central for Cloudmon

Creating a View-Only Administrator Role in Nutanix Prism Central for Cloudmon

Nutanix Monitoring

Creating a View-Only Administrator Role in Nutanix Prism Central for Cloudmon

Follow these steps to assign the Nutanix Objects Viewer role in Prism Central and grant read-only access to Nutanix Objects instances using RBAC.

Overview

This article explains how to grant read-only access to Nutanix Objects instances by assigning the built-in Nutanix Objects Viewer role through Role-Based Access Control (RBAC) in Prism Central. This is the recommended approach for creating a monitoring account with the minimum required permissions.

Prerequisites

  • Administrator access to Prism Central.
  • Users must belong to a Windows Active Directory (AD) group.
  • Nutanix Objects is configured and available in Prism Central.

Procedure

Step 1: Log in to Prism Central

  1. Open the Prism Central web console.
  2. Sign in using an Administrator account.

Step 2: Navigate to Roles

  1. Click the Application Switcher.
  2. Navigate to Admin CenterIAMRoles.

Step 3: Open the Nutanix Objects Viewer Role

  1. Locate the Nutanix Objects Viewer role.
  2. Click Manage Assignment.

The Role Assignment page is displayed.

Step 4: Add a New Role Assignment

  1. Click Add New.
  2. In the Select Users or Groups section:
    • Choose the required Active Directory Group.
    • Search and select the user or user group to grant access.

InfoNotesInfoNote: Only users who are members of a Windows Active Directory group can be assigned this role.

Step 5: Configure Entity Access

  1. In the Entities section:
    • Set Entity Type to Object Store.
    • Select Individual Entity.
    • Choose All Nutanix Objects, or select a specific Nutanix Objects instance to which read-only access should be granted.

Step 6: Save the Assignment

  1. Review the selected user/group and entity.
  2. Click Save.

A view-only access policy is created, granting the selected users or groups read-only access to the specified Nutanix Objects instance(s).

Verification

Verify that the assigned user can:

  • View Nutanix Objects instances.
  • Access object store information.
  • View configuration and status details.
  • Perform read-only operations without administrative privileges.