Specifications

Basic System Administration
268 VMware, Inc.
Mostusershavelimitedabilitytomanipulatetheobjectsassociatedwiththehost.
However,ESXServerprovidefullaccessrightsandpermissionsonallvirtualobjects,
suchasdatastores,hosts,virtualmachines,andresourcepools,totwousers:rootand
vpxuser.
Asroot,youcangrantpermissionsonahostto
individualusersorgroups.Through
VirtualCenter,youcangrantpermissionstoanyuserorgroupincludedinthe
WindowsdomainlistreferencedbyVirtualCenter.
Themethodyouusetoconfigurepermissionsdirectlyonahostisidenticaltothe
methodyouusetoconfigurepermissionsinVirtualCenter .Thelistofprivileges
isthe
sameforESXServerandVirtualCenter.
ThetableinAppendix Aliststheaccesspermissions.
Roles
VirtualCenterandESXServergrantaccesstoobjectsonlytouserswhohavebeen
assignedpermissionsfortheobject.Whenyouassignauserorgrouppermissionsfor
theobject,youdosobypairingtheuserorgroupwitharole.Aroleisapredefinedset
ofprivileges.
VirtualCenter
andESXServerhostsprovidedefaultroles:
SystemrolesSystemrolesarepermanentandtheprivilegesassociatedwith
theserolescannotbechanged.
SamplerolesSamplerolesareprovidedforconvenienceasguidelinesand
suggestions.Theserolescanbemodifiedorremoved.
Youcanalsocreatecompletelynewroles.Table 171liststhedefaultrolesthatcanbe
pairedwithauserandassignedtoanobject.
N
OTEBydefault,alluserswhoaremembersoftheWindowsAdministrators
groupontheVirtualCenterServeraregrantedthesameaccessrightsasanyuser
assignedtotheAdministratorrole.UserswhoaremembersoftheAdministrators
groupcanloginasindividualsandhavefullaccess.
N
OTEWhenyouconnectdirectlytoanESXServerhostusingtheVIClient,youcannot
setvirtualmachineonlypermissions.Tosetpermissionsonindividualvirtual
machines,connecttothehostthroughVirtualCenterServer.