2.0

Table Of Contents
VMware Server User’s Guide
202 VMware, Inc.
GroupMembershipAgroupiscollectionofusers.Ausercanbeamemberof
oneormoregroups.
Groupsprovideaconvenientwaytomanageacollectionofusers.Groupsare
createdandmanagedusingthemechanismsprovidedbythehostoperating
system.
PrivilegesAprivilegeisarighttoperformanindividualactiononanobjector
categoryofobjects.
Forexample,theabilitytopoweronavirtualmachineisaprivilege,inthecategory
ofinteractionswiththevirtualmachineobject.Thisprivilegeistypicallygrouped
inarolewith
otherpoweroperationsonvirtualmachines.Foracompletelistof
availableprivileges,organizedforconveniencebycategory,seeAppendix A,
“DefinedPrivileges,”onpage 299.Privilegescannotbemodified.
RolesAroleisanamedcollectionofprivileges.Rolescanbeassignedtousers
andgroupsonanobjectorcategoryofobjects.
Rolescontroluserandgroupaccesstoobjects.VMware Serverprovidessystem
roles,listedinTable 101,“SystemRoles,”onpage 204.Youcanalsocreateand
manage
userdefinedroles.
PermissionsApermissionisarulethatdeterminesaccesscontrol.Itspecifies
whichrole(collectionofprivileges)isassignedtoauserorgrouponanobjector
categoryofobjects.
Theroleandauserorgroupnamemakeapair.Thispairisassignedtoan
inventoryobject.
Youcanchoosewhetherornotthepermissionispropagatedto
thechildobjectsintheinventoryhierarchy.
Figure 10-1. Permission
inventory object
groupuser
role