5.2

Table Of Contents
Privileges for General Administration Tasks and Commands
An
administrator must have certain privileges to perform general administration tasks and run command line
utilities.
Table 2-14 shows the privileges that are required to perform general administration tasks and run command
line utilities.
Table 2-14. Privileges for General Administration Tasks and Commands
Task Required Privileges
Add or delete a folder Must have the Administrators role on the root folder.
Manage ThinApp applications and settings in View
Administrator
Must have the Administrators role on the root folder.
View and modify View Transfer Server instances and the
Transfer Server repository
Must have the Administrators role on the root folder.
Install View Agent on an unmanaged desktop source, such
as
a physical system, standalone virtual machine, or terminal
server
Register Agent
View or modify configuration settings (except for
administrators) in View Administrator
Manage Global Configuration and Policies
Run all PowerShell commands and command line utilities
except for vdmadmin and vdmimport.
Direct Interaction
Use the vdmadmin and vdmimport commands Must have the Administrators role on the root folder.
Use the vdmexport command Must have the Administrators role or the Administrators
(Read only) role on the root folder.
Best Practices for Administrator Users and Groups
To
increase the security and manageability of your View environment, you should follow best practices when
managing administrator users and groups.
n
Because the Administrators role contains all privileges, assign it to a single user or to a limited set of users.
n
Choose a local Windows user or group to have the Administrators role.
n
Create new user groups for administrators. Avoid using Windows built-in groups or other existing groups
that might contain additional users or groups.
n
Because it is highly visible and easily guessed, avoid using the name Administrator when creating
administrator users and groups.
n
Create folders to segregate sensitive desktops. Delegate the administration of those folders to a limited
set of users.
n
Create separate administrators that can modify global policies and View configuration settings.
Chapter 2 Configuring Role-Based Delegated Administration
VMware, Inc. 53