This portal is to open public enhancement requests against IBM System Storage products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).
We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:
Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,
Post an idea.
Get feedback from the IBM team and other customers to refine your idea.
Follow the idea through the IBM Ideas process.
Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.
IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.
ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.
See this idea on ideas.ibm.com
With the introduction of multi factor authentication in Spectrum Protect, administrative access to the software is significantly increased. However, an administrator without MFA must be used for automated monitoring activities. And for the execution of show commands, for example, system privileges are required.
It is therefore necessary that an administrator can issue all query and show commands on all available resources, but without being able to make changes. Spectrum Protect needs a "read only" system administrator to be able to perform monitoring tasks in an MFA protected environment.
Idea priority | High |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.
Enterprise security is rapidly evolving and is so critical to our client's business. Our Canadian SP clients (very large environments) require this feature to define in conjunction with in its LDAP Groups to ensure the administrators and service based tools can have full view/query capability without any change risk. Corporate security teams are not satisfied with the current mix of roles available to use, as there is no equivalence to read-only administrative permissions, meaning providing no other mix/combination of role, such as policy, domain or node permissions should be used, just read-only. I see the comments dated back into Dec 2022, and this really needs to happen now that we are in 2025. Thank you for your consideration.
Are we looking into a less restrictive "read-only" access?
This request may not be delivered within the release currently under development, but the theme is aligned with the current multi-year strategy. IBM may consider and evaluate any RFE Community feedback for this request through activities such as voting. IBM will update this request in the future.