Specifications

VMware, Inc. 267
Chapter 17 Managing Users, Groups, Permissions, and Roles
ThevpxuseruserisaVirtualCenterentitywithrootrightsontheESXServerhost,
allowingittomanageactivitiesforthathost.Thevpxuseriscreatedatthetimethat
anESXServerhostisattachedtoVirtualCenter.ItisnotpresentontheESX Server
hostunlessthehostis
beingmanagedthroughVirtualCenter .
ForinformationoncreatingusersandgroupsforusewithVirtualCenterServer,see
Microsoftdocumentation.
ForinformationoncreatingusersandgroupforusewithESXServer,seetheSecurity
sectionoftheESXServer3ConfigurationGuideorESXServer3iConfigurationGuide.
Groups
Youcanefficientlymanagesomeuserattributesbycreatinggroups.Agroupisasetof
usersthatyouwanttomanagethroughacommonsetofrulesandpermissions.When
youassignpermissionstoagroup,theyareinheritedbyallusersinthegroup.Using
groupscansignificantlyreduce
thetimeittakestosetupyourpermissionsmodel.
ThegrouplistsinVirtualCenterandanESXServerhostaredrawnfromthesame
sourcesastheuserlists.IfyouareworkingthroughVirtualCenter,thegrouplistis
calledfromtheWindowsdomain.Ifyouareloggedonto
anESXServerhostdirectly,
thegrouplistiscalledfromatablemaintainedbythehost.
TheVirtualCenterServergrantsaccesstoeachinventoryobjectbyassigningarolewith
definedprivilegesandauserorgrouptoeachobject.Rolesareadefinedsetofaccess
privileges.
Individualpermissions
areassignedthroughtheVirtualCenterServerortheESX
Serverhostbypairingauserandaroleandassigningthispairtoaninventoryobject.
Permissions
InVMwareInfrastructure,apermissionisdefinedasanaccessrolethatconsistsofa
userandtheusersassignedroleforanobject,suchasavirtualmachineorESXServer
host.Permissionsgrantuserstherighttoperformspecificactivitiesandmanage
specificobjectsonaspecifichostor,
ifusersareworkingfromVirtualCenter,all
VirtualCentermanagedobjects.Forexample,toconfigurememoryforanESXServer
host,youmusthavehostconfigurationpermissions.
CAUTIONDonotchangevpxuseranddonotchangeitspermissions.Ifyoudoso,you
mightexperienceproblemsworkingwiththeESXServerhostthroughVirtualCenter.