Administration

Table Of Contents
Configuring Role-Based
Delegated Administration 6
One key management task in a View environment is to determine who can use View Administrator and
what tasks those users are authorized to perform. With role-based delegated administration, you can
selectively assign administrative rights by assigning administrator roles to specific Active Directory users
and groups.
This section includes the following topics:
n
Understanding Roles and Privileges
n
Using Access Groups to Delegate Administration of Pools and Farms
n
Understanding Permissions
n
Manage Administrators
n
Manage and Review Permissions
n
Manage and Review Access Groups
n
Manage Custom Roles
n
Predefined Roles and Privileges
n
Required Privileges for Common Tasks
n
Best Practices for Administrator Users and Groups
Understanding Roles and Privileges
The ability to perform tasks in View Administrator is governed by an access control system that consists
of administrator roles and privileges. This system is similar to the vCenter Server access control system.
An administrator role is a collection of privileges. Privileges grant the ability to perform specific actions,
such as entitling a user to a desktop pool. Privileges also control what an administrator can see in View
Administrator. For example, if an administrator does not have privileges to view or modify global policies,
the Global Policies setting is not visible in the navigation panel when the administrator logs in to View
Administrator.
Administrator privileges are either global or object-specific. Global privileges control system-wide
operations, such as viewing and changing global settings. Object-specific privileges control operations on
specific types of objects.
VMware, Inc.
115