Administration

Table Of Contents
Table 68. Object-Specific Privileges (Continued)
Privilege User Capabilities Object
Manage Machine Perform all machine and session-related operations. Machine
Manage Persistent Disks Perform all View Composer persistent disk operations,
including attaching, detaching, and importing persistent
disks.
Persistent disk
Manage Farms and Desktop
and Application Pools
Add, modify, and delete farms. Add, modify, delete, and
entitle desktop and application pools. Add and remove
machines.
Desktop pool, application pool,
farm
Manage Sessions Disconnect and log off sessions and send messages to
users.
Session
Manage Reboot Operation Reset virtual machines or restart virtual desktops. Machine
Internal Privileges
Some of the predefined administrator roles contain internal privileges. You cannot select internal
privileges when you create custom roles.
Table 69 describes the internal privileges and lists the predefined roles that contain each privilege.
Table 69. Internal Privileges
Privilege Description Predefined Roles
Full (Read only) Grants read-only access to all settings. Administrators (Read only)
Manage Inventory
(Read only)
Grants read-only access to inventory objects. Inventory Administrators (Read only)
Manage Global
Configuration and
Policies (Read only)
Grants read-only access to configuration
settings and global policies except for
administrators and roles.
Global Configuration and Policy Administrators
(Read only)
Required Privileges for Common Tasks
Many common administration tasks require a coordinated set of privileges. Some operations require
permission at the root access group in addition to access to the object that is being manipulated.
Privileges for Managing Pools
An administrator must have certain privileges to manage pools in Horizon Administrator.
Table 610 lists common pool management tasks and shows the privileges that are required to perform
each task.
Table 610. Pool Management Tasks and Privileges
Task Required Privileges
Enable or disable a desktop pool Enable Farms and Desktop Pools
Entitle or unentitle users to a pool Entitle Desktop and Application Pools
View Administration
VMware, Inc. 131