1.0

Table Of Contents
VMware, Inc. 37
Chapter 4 Managing SRM
SRM Users, Groups, Permissions, and Roles
SRMusesthesameauthorizationmodelasVirtualCenterServer.Thesetofpermissions
appliedtoorinheritedbyanobjectdeterminetheoperationsthatareallowedonthe
objectandthelistofrolesthatcanperformthoseoperations.Managedobjectsinthe
SRMinventorycanhavespecificpermissionsapplied.There
aretwowaystocontrol
permissiontoexecuteSRMoperations:
AddingusersAssignuserstothepredefinedroles.
AddingrolesCreatearole,addtheadministrators,andthenaddtheright
permissionstotherole.
Tomanagepermissionsandroles,youmustlogintotheVirtualCenterServerwiththe
administratoraccount.
ThePermissionstabliststheusersandgroupsthathavepermissionsontheselected
objectandat
whatlevelthepermissionwasassigned.
YoumustbeinAdministrationviewfortheRolesmenuitemtobeenabled.
The Permissionstabdisplaysthefollowing:
User/Group—TheuserorgroupthatexistsinSRM.
Role—Setofprivilegesassignedtoanexistinguserorgroup.
Definedin—Theobjectinwhichtheuser,group,androleisdefined.
SRM Permissions
Toobtainthefullabilityofanadministratoroftheprotectedsiteandtherecoverysite,
definethefollowingpermissions:
Protectedsite:
ReadonlyattheVirtualCenterroot(donotpropagate).
ReadonlytoDatacenterinventoryobject(donotpropagate).
ProtectionVirtualMachineAdministratorroleattheVirtualMachinelevel
(propagate).
NOTEToconfigureSRM,ausermusthavebothVirtualCenterandSRMpermissions.
SRMrolessuchasSRMProtectionAdministratorandSRMRecoveryAdministratordo
nothavespecificprivilegesforVirtualCenterandthereforedonothaveadequate
permissionstoperformallSRMoperations.Theconverseisalsotrue.VirtualCenter
rolesdo
notprovideanySRMprivileges.EnsurethatSRMusershaveVirtualCenter
andSRMspecificrolesasappropriate.