Administration

Table Of Contents
n
Global Privileges
Global privileges control system-wide operations, such as viewing and changing global settings.
Roles that contain only global privileges cannot be applied to access groups.
n
Object-Specific Privileges
Object-specific privileges control operations on specific types of inventory objects. Roles that contain
object-specific privileges can be applied to access groups.
n
Internal Privileges
Some of the predefined administrator roles contain internal privileges. You cannot select internal
privileges when you create custom roles.
Predefined Administrator Roles
The predefined administrator roles combine all of the individual privileges required to perform common
administration tasks. You cannot modify the predefined roles.
Table 66 describes the predefined roles and indicates whether a role can be applied to an access group.
Table 66. Predefined Roles in Horizon Administrator
Role User Capabilities
Applies to an Access
Group
Administrators Perform all administrator operations, including creating additional
administrator users and groups. In a Cloud Pod Architecture
environment, administrators that have this role can configure and
manage a pod federation and manage remote pod sessions.
Administrators that have the Administrators role on the root access
group are super users because they have full access to all of the
inventory objects in the system. Because the Administrators role
contains all privileges, you should assign it to a limited set of users.
Initially, members of the local Administrators group on your Connection
Server host are given this role on the root access group.
Important An administrator must have the Administrators role on the
root access group to perform the following tasks:
n
Add and delete access groups.
n
Manage ThinApp applications and configuration settings in Horizon
Administrator.
n
Use the vdmadmin , vdmimport, and lmvutil commands.
Yes
Administrators (Read only)
n
View, but not modify, global settings and inventory objects.
n
View, but not modify, ThinApp applications and settings.
n
Run all PowerShell commands and command line utilities,
including vdmexport but excluding vdmadmin, vdmimport and
lmvutil.
In a Cloud Pod Architecture environment, administrators that have this
role can view inventory objects and settings in the Global Data Layer.
When administrators have this role on an access group, they can only
view the inventory objects in that access group.
Yes
View Administration
VMware, Inc. 126