Specifications
Basic System Administration
262 VMware, Inc.
“Users”onpage 265
“Groups”onpage 267
“Permissions”onpage 267
“Roles”onpage 268
“A c c e s s Permissions”onpage 274
Access Elements
AccesstoVMwareInfrastructureobjectsandactivitiesisestablishedthroughthe
combinationof:
LogIninformation–Usernameandpassword.
Groups–Amethodforgroupingindividualusers.
Youcanmanageusersmoreeasilybyassigningthemtogroups.Ifyoucreate
groups,youcanapplyaroletothegroup,andthisroleisinheritedbyalltheusers
inthegroup.
Roles–Adefinedcollectionofprivileges.
Rolesareacollectionofdefinedprivilegesthatcontrolindividualuserorgroup
accesstoparticularVMwareInfrastructureobjects.ESXServerandVirtualCenter
Serverprovideasetofdefaultroles.Youcanalsocreatenewroles.
Privileges–Aparticularrightcorrespondingtoasetofoperationsormethodson
aclassofobjects.
Permissions–Thecombinationoftheroleplususerorgroupnameassignedtoa
VMwareInfrastructureinventoryobject.
Theroleandauserorgroupnamemakeapair.ThispairisassignedtoaVMware
Infrastructureobject.Typically ,thisroleanduserpairingispropagatedtothe
childrenin
theinventoryhierarchy.Thepairiscalledapermission.
Access Rules
Thefollowingisalistofgeneralrulestoconsiderwhenconfiguringyouruser’sand
group’spermissions.
Usersdonotneedtologoutandloginforchangestotakeeffect.Allchangestakeeffect
immediately.