6.0.3

Table Of Contents
n
Users who are in a domain that is not a vCenter Single Sign-On identity source cannot log in to
vCenter Server. If the domain that you add to vCenter Single Sign-On is part of a domain hierarchy,
Active Directory determines whether users of other domains in the hierarchy are authenticated or not.
N If your environment includes an Active Directory hierarchy, see VMware Knowledge Base article
2064250 for details on supported and unsupported setups.
Groups in the vsphere.local Domain
The vsphere.local domain includes several predened groups. Assign users to one of those groups to be able
to perform the corresponding actions.
For all objects in the vCenter Server hierarchy, permissions are assigned by pairing a user and a role with the
object. For example, you can select a resource pool and give a group of users read privileges to that resource
pool by giving them the corresponding role.
For some services that are not managed by vCenter Server directly, privileges are determined by
membership to one of the vCenter Single Sign-On groups. For example, a user who is a member of the
Administrator group can manage vCenter Single Sign-On. A user who is a member of the CAAdmins group
can manage the VMware Certicate Authority, and a user who is in the LicenseService.Administrators
group can manage licenses.
The following groups are predened in vsphere.local.
N Many of these groups are internal to vsphere.local or give users high-level administrative privileges.
Add users to any of these groups only after careful consideration of the risks.
N Do not delete any of the predened groups in the vsphere.local domain. If you do, errors with
authentication or certicate provisioning might result.
Table 24. Groups in the vsphere.local Domain
Privilege Description
Users Users in the vsphere.local domain.
SolutionUsers Solution users group vCenter services. Each solution user authenticates
individually to vCenter Single Sign-On with a certicate. By default, VMCA
provisions solution users with certicates. Do not add members to this group
explicitly.
CAAdmins Members of the CAAdmins group have administrator privileges for VMCA.
Adding members to these groups is not usually recommended.
DCAdmins Members of the DCAdmins group can perform Domain Controller
Administrator actions on VMware Directory Service.
N Do not manage the domain controller directly. Instead, use the vmdir CLI
or vSphere Web Client to perform corresponding tasks.
SystemConguration.BashShellAdmi
nistrators
This group is available only for vCenter Server Appliance deployments.
A user in this group can enable and disable access to the BASH shell. By default
a user who connects to the vCenter Server Appliance with SSH can access only
commands in the restricted shell. Users who are in this group can access the
BASH shell.
ActAsUsers Members of Act-As Users are allowed to get actas tokens from vCenter Single
Sign-On.
ExternalIPDUsers This group is not used by vSphere. This group is needed in conjunction with
VMware vCloud Air.
Chapter 2 vSphere Authentication with vCenter Single Sign-On
VMware, Inc. 27