Administration

Table Of Contents
Table 6-15. Privileges for General Administration Tasks and Commands
Task Required Privileges
Add or delete an access group Must have the Local Administrators role or Administrators
role on the root access group for deleting an access
group.
Must have the Inventory Administrators or Local
Administrators or Administrators role on the root access
group.
Manage ThinApp applications and settings in Horizon
Administrator
Must have the Administrators role on the root access
group.
Install Horizon Agent on an unmanaged machine, such as
a physical system, standalone virtual machine, or RDS host
Register Agent
View or modify configuration settings (except for
administrators) in Horizon Administrator
Manage Global Configuration and Policies
Run all PowerShell commands and command line utilities
except for vdmadmin and vdmimport.
Direct Interaction
Note Starting in Horizon 7 version 7.10, the Direct
Interaction privilege is automatically added to new roles
and is not visible in the list of privileges in Horizon
Console.
Use the vdmadmin and vdmimport commands Must have the Administrators role on the root access
group.
Use the vdmexport command Must have the Administrators role or the Administrators
(Read only) role on the root access group.
Read only access to vCenter Server configuration. Manage vCenter Configuration (Read only)
Best Practices for Administrator Users and Groups
To increase the security and manageability of your Horizon 7 environment, you should follow best
practices when managing administrator users and groups.
n Create new user groups in Active Directory and assign administrative roles to these groups.
Avoid using Windows built-in groups or other existing groups that might contain users who do
not need or should not have Horizon 7 privileges.
n Keep the number of users with Horizon 7 administrative privileges to a minimum.
n Because the Administrators role has every privilege, it should not be used for day-to-day
administration.
n Because it is highly visible and easily guessed, avoid using the name Administrator when
creating administrator users and groups.
n Create access groups to segregate sensitive desktops and farms. Delegate the administration
of those access groups to a limited set of users.
n Create separate administrators that can modify global policies and Horizon 7 configuration
settings.
Horizon 7 Administration
VMware, Inc. 147