Specifications
Basic System Administration
268 VMware, Inc.
Mostusershavelimitedabilitytomanipulatetheobjectsassociatedwiththehost.
However,ESXServerprovidefullaccessrightsandpermissionsonallvirtualobjects,
suchasdatastores,hosts,virtualmachines,andresourcepools,totwousers:rootand
vpxuser.
Asroot,youcangrantpermissionsonahostto
individualusersorgroups.Through
VirtualCenter,youcangrantpermissionstoanyuserorgroupincludedinthe
WindowsdomainlistreferencedbyVirtualCenter.
Themethodyouusetoconfigurepermissionsdirectlyonahostisidenticaltothe
methodyouusetoconfigurepermissionsinVirtualCenter .Thelistofprivileges
isthe
sameforESXServerandVirtualCenter.
ThetableinAppendix Aliststheaccesspermissions.
Roles
VirtualCenterandESXServergrantaccesstoobjectsonlytouserswhohavebeen
assignedpermissionsfortheobject.Whenyouassignauserorgrouppermissionsfor
theobject,youdosobypairingtheuserorgroupwitharole.Aroleisapredefinedset
ofprivileges.
VirtualCenter
andESXServerhostsprovidedefaultroles:
Systemroles–Systemrolesarepermanentandtheprivilegesassociatedwith
theserolescannotbechanged.
Sampleroles–Samplerolesareprovidedforconvenienceasguidelinesand
suggestions.Theserolescanbemodifiedorremoved.
Youcanalsocreatecompletelynewroles.Table 17‐1liststhedefaultrolesthatcanbe
pairedwithauserandassignedtoanobject.
N
OTEBydefault,alluserswhoaremembersoftheWindowsAdministrators
groupontheVirtualCenterServeraregrantedthesameaccessrightsasanyuser
assignedtotheAdministratorrole.UserswhoaremembersoftheAdministrators
groupcanloginasindividualsandhavefullaccess.
N
OTEWhenyouconnectdirectlytoanESXServerhostusingtheVIClient,youcannot
setvirtualmachine‐onlypermissions.Tosetpermissionsonindividualvirtual
machines,connecttothehostthroughVirtualCenterServer.