7.3

Table Of Contents
System-Wide Roles and Responsibilities
Users with system-wide roles manage configurations that can apply to multiple tenants. The system
administrator is only present in the default tenant, but you can assign IaaS administrators to any tenant.
Table 23. System-Wide Roles and Responsibilities
Role Responsibilities How Assigned
System Administrator
n
Create tenants.
n
Configure tenant identity stores.
n
Assign IaaS administrator role.
n
Assign tenant administrator role.
n
Configure system default branding.
n
Configure system default notification providers.
n
Monitor system event logs, not including IaaS logs.
n
Configure the vRealize Orchestrator server for use
with XaaS.
n
Create and manage (view, edit, and delete)
reservations across tenants if also a fabric
administrator.
Built-in administrator credentials are
specified when configuring single sign-on.
IaaS Administrator
n
Configure IaaS features, global properties.
n
Create and manage fabric groups.
n
Create and manage endpoints.
n
Manage endpoint credentials.
n
Configure proxy agents.
n
Manage Amazon AWS instance types.
n
Monitor IaaS-specific logs.
n
Create and manage (view, edit, and delete)
reservations across tenants if also a fabric
administrator.
The system administrator designates the
IaaS administrator when configuring a
tenant.
Foundations and Concepts
VMware, Inc. 22