Specifications
VMware, Inc. 261
17
Thischapterdescribesusers,groups,permissions,androles.VirtualCenterandESX
Serverhostsdeterminethelevelofaccessfortheuserbasedonthepermissions
assignedtotheuser.Thecombinationofusername,password,andpermissionsisthe
mechanismbywhichVirtualCenterandESXServerhostsauthenticateauserfor
access
andauthorizetheusertoperformactivities.Theserversandhostsmaintainlistsof
authorizedusersandthepermissionsassignedtoeachuser.
Privilegesdefinebasicindividualrightsrequiredtoperformactionsandread
properties.ESXServerandVirtualCenterusesetsofprivileges,orroles,tocontrol
whichindividual
usersorgroupscanaccessparticularVMwareInfrastructureobjects.
ESXServerandVirtualCenterprovideasetofpre‐establishedroles.Youcanalsocreate
newroles.
TheprivilegesandrolesassignedonanESXServerhostareseparatefromthe
privilegesandrolesassignedonaVirtualCenterServer.Ifyouhave
privilegesandroles
assignedonanESXServerhostandthenaddthathosttotheVirtualCenterServer
inventory,onlytheprivilegesandrolesassignedthroughtheVirtualCenterServerare
recognized.IfyouthenremovethehostfromtheVirtualCenterServerinventory,the
previouslysetESXServerhostprivilegesandroles
areused.
Foracompletelistofprivilegesavailable,seeAppendix A,“DefinedPrivileges,”on
page 327.
Thischaptercontainsthefollowingtopics:
“A c c e s s Elements”onpage 262
“A c c e s s Rules”onpage 262
Managing Users, Groups,
Permissions, and Roles
17
NOTEYoumustbeinAdminviewfortheAdmin>Rolesmenuitemtobeenabled.