Specifications

Basic System Administration
266 VMware, Inc.
AnychangesyoumaketotheWindowsdomainarereflectedinVirtualCenter.
BecauseyoucannotdirectlymanageusersinVirtualCenter,theuserinterface
doesn’tprovideauserlistforyoutoreview.Youseethesechangesonlywhenyou
selectuserstoconfigurepermissions.
DirectaccessusersUsersauthorizedtoworkdirectlyonanESXServerhostare
thoseaddedtotheinternaluserlistbydefaultwhenESXServerisinstalledorby
asystemadministratorafterinstallation.
IfyoulogintoanESXServerhostasrootusingtheVIClient,
youcanperforma
varietyofmanagementactivitiesfortheseusers,suchaschangingpasswords,
groupmemberships,permissions,andsoforth.Youcanalsoaddandremove
users.
EvenifthelistsmaintainedbyanESXServerhostandVirtualCenterappeartohave
commonusers(forinstance,ausercalled
devuser),theseusersshouldbetreatedas
separateuserswhohavethesamename.TheattributesofdevuserinVirtualCenter,
includingpermissions,passwords,andsoforth,areseparatefromtheattributesof
devuserontheESXServerhost.IfyoulogintoVirtualCenterasdevuser,youmighthave
permission
toviewanddeletefilesfromadatastore.IfyoulogintoanESXServerhost
asdevuser,youmightnot.
UsersandgroupsintheVMwareInfrastructureenvironmentarecreatedusingthe
followingmethods:
WhentheVIClientisconnectedtoaVirtualCenterServersystem,usersand
groupsaredefinedthroughthestandardmethodsforWindowsdomainsorActive
Directory.YoudonotcreateusersandgroupsforaccesstotheVirtualCenterServer
throughtheVIClient.
WhentheVIClientisconnectedtoanESXServerhost,usersandgroupsare
definedthroughtheUsersandGroupstab.
EachESXServerhosthastwodefaultusers:
Therootuserhasfulladministrativeprivileges.Administratorsusethisloginand
itsassociatedpasswordtologintoahostthroughtheVIClient.Rootusershavea
completerangeofcontrolactivitiesonthespecifichostthattheyareloggedonto,
includingmanipulatingpermissions,creatinggroupsand
users,workingwith
events,andsoforth.
WARNINGSeetheAuthenticationandUserManagementchapteroftheESXServer3
ConfigurationGuideorESXServer3iConfigurationGuideforinformationaboutrootusers
andyourESXServerbeforeyoumakeanychangestotherootuser.Mistakesherecan
haveseriousaccessconsequences.