Specifications
Basic System Administration
264 VMware, Inc.
Ifthereisnopermissiondefinedexplicitlyfortheuseronthatobject,theuser
isassignedtheunionofprivilegesassignedtothegroupsforthatobject.
Ifthereisapermissiondefinedexplicitlyfortheuseronthatobject,that
permissiontakesprecedenceoverallgrouppermissions.
Example1:Expandingauser’spermissions
Role1canpoweronvirtualmachines.
Role2cantakesnapshotsofvirtualmachines.
GroupAisgrantedRole1onvirtualmachine.
GroupBisgrantedRole2onvirtualmachine.
User1isnotassignedspecificpermission:
User1,whobelongstogroupsAandB,logson.
User1canbothpoweronandtakesnapshotsofvirtualmachine.
Example2:Limitingauser’spermissions
Role1canpoweronvirtualmachines.
Role2cantakesnapshotsofvirtualmachines.
GroupAisgrantedRole1onvirtualmachineparentfolder.
GroupBisgrantedRole2onvirtualmachine.
User1ReadOnlypermissionisremovedonvirtualmachine:
User1cantakesnapshotsbutnotpoweron.
Tasks Requiring Settings on Multiple Objects
Whensettingpermissions,verifythatalltheobjecttypesaresetwithappropriate
privilegesforeachparticularaction.Someoperationsrequireaccesspermissionatthe
rootfolderinadditiontoaccesspermissionsontheobjectbeingmanipulated.Some
operationsrequireaccessorperformancepermissionataparentfolderandarelated
object.
SeeAppendix A,“DefinedPrivileges,”onpage 327foralistofpredefinedrolesand
associatedprivileges.Usethesepredefinedrolestohelpdeterminetherole+object
pairingrequiredtoperformyourchosentask.