6.0

Table Of Contents
Configuring Role-Based Delegated
Administration 4
One key management task in a View environment is to determine who can use View Administrator and
what tasks those users are authorized to perform. With role-based delegated administration, you can
selectively assign administrative rights by assigning administrator roles to specific Active Directory users
and groups.
This chapter includes the following topics:
n
“Understanding Roles and Privileges,” on page 61
n
“Using Access Groups to Delegate Administration of Pools and Farms,” on page 62
n
“Understanding Permissions,” on page 63
n
“Manage Administrators,” on page 64
n
“Manage and Review Permissions,” on page 65
n
“Manage and Review Access Groups,” on page 67
n
“Manage Custom Roles,” on page 69
n
“Predefined Roles and Privileges,” on page 71
n
“Required Privileges for Common Tasks,” on page 75
n
“Best Practices for Administrator Users and Groups,” on page 77
Understanding Roles and Privileges
The ability to perform tasks in View Administrator is governed by an access control system that consists of
administrator roles and privileges. This system is similar to the vCenter Server access control system.
An administrator role is a collection of privileges. Privileges grant the ability to perform specific actions,
such as entitling a user to a desktop pool. Privileges also control what an administrator can see in View
Administrator. For example, if an administrator does not have privileges to view or modify global policies,
the Global Policies setting is not visible in the navigation panel when the administrator logs in to View
Administrator.
Administrator privileges are either global or object-specific. Global privileges control system-wide
operations, such as viewing and changing global settings. Object-specific privileges control operations on
specific types of objects.
Administrator roles typically combine all of the individual privileges required to perform a higher-level
administration task. View Administrator includes predefined roles that contain the privileges required to
perform common administration tasks. You can assign these predefined roles to your administrator users
and groups, or you can create your own roles by combining selected privileges. You cannot modify the
predefined roles.
VMware, Inc.
61