Specifications

Basic System Administration
262 VMware, Inc.
“Users”onpage 265
“Groups”onpage 267
“Permissions”onpage 267
“Roles”onpage 268
“A c c e s s Permissions”onpage 274
Access Elements
AccesstoVMwareInfrastructureobjectsandactivitiesisestablishedthroughthe
combinationof:
LogIninformationUsernameandpassword.
GroupsAmethodforgroupingindividualusers.
Youcanmanageusersmoreeasilybyassigningthemtogroups.Ifyoucreate
groups,youcanapplyaroletothegroup,andthisroleisinheritedbyalltheusers
inthegroup.
RolesAdefinedcollectionofprivileges.
Rolesareacollectionofdefinedprivilegesthatcontrolindividualuserorgroup
accesstoparticularVMwareInfrastructureobjects.ESXServerandVirtualCenter
Serverprovideasetofdefaultroles.Youcanalsocreatenewroles.
PrivilegesAparticularrightcorrespondingtoasetofoperationsormethodson
aclassofobjects.
PermissionsThecombinationoftheroleplususerorgroupnameassignedtoa
VMwareInfrastructureinventoryobject.
Theroleandauserorgroupnamemakeapair.ThispairisassignedtoaVMware
Infrastructureobject.Typically ,thisroleanduserpairingispropagatedtothe
childrenin
theinventoryhierarchy.Thepairiscalledapermission.
Access Rules
Thefollowingisalistofgeneralrulestoconsiderwhenconfiguringyourusersand
group’spermissions.
Usersdonotneedtologoutandloginforchangestotakeeffect.Allchangestakeeffect
immediately.