5.2

Table Of Contents
Table 2-6. Predefined Roles in View Administrator
Role User Capabilities Applies to a Folder
Administrators Perform all administrator operations, including creating
additional administrator users and groups. Administrators that
have the Administrators role on the root folder are super
administrators because they have full access to all of the inventory
objects in the system. Because the Administrators role contains all
privileges, you should assign it to a limited set of users.
Initially, members of the local Administrators group on your View
Connection Server host are given this role on the root folder.
IMPORTANT An administrator must have the Administrators role
on the root folder to perform the following tasks:
n
Add and delete folders.
n
Manage ThinApp applications and configuration settings in
View Administrator.
n
View and modify View Transfer Server instances and the
Transfer Server repository.
n
Use the vdmadmin and vdmimport commands.
Yes
Administrators (Read only)
n
View, but not modify, global settings and inventory objects.
n
View, but not modify, ThinApp applications and settings,
View Transfer Server instances, and the Transfer Server
repository.
n
Run all PowerShell commands and command line utilities,
including vdmexport but excluding vdmadmin and
vdmimport.
When
administrators have this role on a folder, they can only view
the inventory objects in that folder.
Yes
Agent Registration
Administrators
Register unmanaged desktop sources such as physical systems,
standalone virtual machines, and terminal servers.
No
Global Configuration and
Policy Administrators
View and modify global policies and configuration settings except
for
administrator roles and permissions, ThinApp applications and
settings, View Transfer Server instances, and the Transfer Server
repository.
No
Global Configuration and
Policy Administrators (Read
only)
View, but not modify, global policies and configuration settings
except for administrator roles and permissions, ThinApp
applications and settings, View Transfer Server instances, and the
Transfer Server repository.
No
Inventory Administrators
n
Perform all desktop, session, and pool-related operations.
n
Manage persistent disks.
n
Resync, Refresh, and Rebalance linked-clone pools and change
the default pool image.
When administrators have this role on a folder, they can only
perform these operations on the inventory objects in that folder.
Yes
Inventory Administrators
(Read only)
View, but not modify, inventory objects.
When administrators have this role on a folder, they can only view
the inventory objects in that folder.
Yes
Global Privileges
Global privileges control system-wide operations, such as viewing and changing global settings. Roles that
contain only global privileges cannot be applied to folders.
Table 2-7 describes the global privileges and lists the predefined roles that contain each privilege.
Chapter 2 Configuring Role-Based Delegated Administration
VMware, Inc. 49