6.1

Table Of Contents
3 Select the group you just created and use the Group Members section of the tab to add a delegated
administrator user to this group.
This user must be a member of the domain that includes the View Connection Server instance.
4 Create a role that has permission to read vCenter extensions.
a Browse to Administration > Roles.
b On the Roles tab, click the Create role action icon.
c Supply a name for the role and select the Extensions check box.
If you expand the Extensions item, you see that the Register extension, Unregister extension, and
Update extension check boxes are also selected.
d Click OK.
The new role appears in the list.
5 Add the new role you just created to the new group you created.
a Go to the vCenter Home page and browse to vCenter > Inventory Lists > vCenters.
b Select the appropriate vCenter instance in the left pane, and click the Manage tab.
c On the Manage tab, click Permissions and click the Add permission icon.
d In the Users and Groups pane, click Add and add the group you just created.
To find the group, select the correct domain.
The group appears in the list of users and groups in the Add Permission dialog box.
e In the Assigned Role pane, click the drop-down arrow and select the role you just created.
In the list of permissions for this role, a check mark appears next to Extensions.
f Click OK.
The group appears on the Permissions tab, along with the role you just assigned.
What to do next
Provide the Delegated Administrators group access to the Horizon vRealize Orchestrator plug-in
workflows. See “Provide Access Rights to the Horizon vRealize Orchestrator Plug-In Workflows,” on
page 19.
Provide Access Rights to the Horizon vRealize Orchestrator Plug-In Workflows
After you create a delegated administrators group and assign it permission to perform actions on vCenter
extensions, you can give the group permission to view and execute workflows in Orchestrator.
If you have been using vRealize Orchestrator and have already created users and groups that have
permission to view, inspect, and execute vCenter extensions, you might not need to perform the procedure
described in this topic.
Prerequisites
n
Verify that you have administrator credentials for the Orchestrator server. The account must be a
member of the vRealize Orchestrator Admin group configured to authenticate through vCenter Single
Sign-On.
n
Verify that you have created a delegated administrators group and assigned a role that has Extensions
permissions in vCenter. See “Create a Delegated Administrator Role Using vSphere Web Client,” on
page 18.
Chapter 2 Installing and Configuring the Horizon vRealize Orchestrator Plug-In
VMware, Inc. 19