Reference Guide
A secure Administration Console session has a 15 minutes idle time-out, and the session is only valid in the current browser
window and/or tab. If you try to open the session in a new window or tab, a security error is prompted that asks for a valid
session. This action also prevents the user from clicking any malicious URL that can attack the Administration Console session.
Figure 2. Security error message
Access control authentication, authorization, and roles
To perform vCenter operations, OpenManage Integration for VMware vCenter uses the current user session of vSphere client
and the stored administration credentials for the OpenManage Integration. The OpenManage Integration for VMware vCenter
uses the vCenter server's built-in roles and privileges model to authorize user actions with the OpenManage Integration and the
vCenter managed objects (hosts and clusters).
Dell Operational role
The role contains the privileges/groups to accomplish appliance and vCenter server tasks including firmware updates, hardware
inventory, restarting a host, placing a host in maintenance mode, or creating a vCenter server task.
This role contains the following privilege groups:
Table 2. Privilege groups
Group name Description
Privilege group—Dell.Configuration Perform Host-related tasks, Perform vCenter-related tasks,
Configure SelLog, Configure ConnectionProfile, Configure
ClearLed, Firmware Update
Privilege group—Dell.Inventory Configure inventory, Configure warranty retrieval, Configure
readonly
Privilege group—Dell.Monitoring Configure monitoring, monitor
Privilege group—Dell. Reporting (Not used) Create a report, Run a report
Dell Infrastructure Deployment role
The role contains the privileges that are related to the hypervisor deployment features.
The privileges this role provides are Configure Host Credential Profile, Assign Identity, and Deploy.
Privilege Group — Dell.Deploy-Provisioning
Configure Host Credential Profile, Assign Identity, Deploy.
About privileges
Every action that is performed by the OpenManage Integration for VMware vCenter is associated with a privilege. The following
sections list the available actions and the associated privileges:
● Dell.Configuration.Perform vCenter-related tasks
○ Exit and enter maintenance mode
○ Get the vCenter user group to query the permissions
○ Register and configure alarms, for example enable/disable alarms on the event settings page
Product and Subsystem Security
15