Administration

Table Of Contents
Configuring Role-Based
Delegated Administration
6
One key management task in an Horizon 7 environment is to determine who can use Horizon
Administrator and what tasks those users are authorized to perform. With role-based delegated
administration, you can selectively assign administrative rights by assigning administrator roles to
specific Active Directory users and groups.
This chapter includes the following topics:
n Understanding Roles and Privileges
n Using Access Groups to Delegate Administration of Pools and Farms
n Understanding Permissions
n Manage Administrators
n Manage and Review Permissions
n Manage and Review Access Groups
n Manage Custom Roles
n Predefined Roles and Privileges
n Required Privileges for Common Tasks
n Best Practices for Administrator Users and Groups
Understanding Roles and Privileges
The ability to perform tasks in Horizon Administrator is governed by an access control system that
consists of administrator roles and privileges. This system is similar to the vCenter Server access
control system.
An administrator role is a collection of privileges. Privileges grant the ability to perform specific
actions, such as entitling a user to a desktop pool. Privileges also control what an administrator
can see in Horizon Administrator. For example, if an administrator does not have privileges to view
or modify global policies, the Global Policies setting is not visible in the navigation panel when the
administrator logs in to Horizon Administrator.
Administrator privileges are either global or object-specific. Global privileges control system-wide
operations, such as viewing and changing global settings. Object-specific privileges control
operations on specific types of objects.
VMware, Inc.
125