5.2

Table Of Contents
Configuring Role-Based Delegated
Administration 2
One key management task in a View environment is to determine who can use View Administrator and what
tasks those users are authorized to perform. With role-based delegated administration, you can selectively
assign administrative rights by assigning administrator roles to specific Active Directory users and groups.
This chapter includes the following topics:
n
“Understanding Roles and Privileges,” on page 39
n
“Using Folders to Delegate Administration,” on page 40
n
“Understanding Permissions,” on page 41
n
“Manage Administrators,” on page 42
n
“Manage and Review Permissions,” on page 43
n
“Manage and Review Folders,” on page 45
n
“Manage Custom Roles,” on page 47
n
“Predefined Roles and Privileges,” on page 48
n
“Required Privileges for Common Tasks,” on page 51
n
“Best Practices for Administrator Users and Groups,” on page 53
Understanding Roles and Privileges
The ability to perform tasks in View Administrator is governed by an access control system that consists of
administrator roles and privileges. This system is similar to the vCenter Server access control system.
An
administrator role is a collection of privileges. Privileges grant the ability to perform specific actions, such
as entitling a user to a desktop pool. Privileges also control what an administrator can see in View
Administrator. For example, if an administrator does not have privileges to view or modify global policies,
the Global Policies setting is not visible in the navigation panel when the administrator logs in to View
Administrator.
Administrator privileges are either global or object-specific. Global privileges control system-wide operations,
such as viewing and changing global settings. Object-specific privileges control operations on specific types
of inventory objects.
Administrator roles typically combine all of the individual privileges required to perform a higher-level
administration task. View Administrator includes predefined roles that contain the privileges required to
perform common administration tasks. You can assign these predefined roles to your administrator users and
groups, or you can create your own roles by combining selected privileges. You cannot modify the predefined
roles.
VMware, Inc. 39