7.1

Table Of Contents
System-Wide Roles and Responsibilities
Users with system-wide roles manage congurations that can apply to multiple tenants. The system
administrator is only present in the default tenant, but you can assign IaaS administrators to any tenant.
Table 3. System-Wide Roles and Responsibilities
Role Responsibilities How Assigned
System Administrator
n
Create tenants.
n
Congure tenant identity stores.
n
Assign IaaS administrator role.
n
Assign tenant administrator role.
n
Congure system default branding.
n
Congure system default notication
providers.
n
Monitor system event logs, not including IaaS
logs.
n
Congure the vRealize Orchestrator server for
use with XaaS.
n
Create and manage (view, edit, and delete)
reservations across tenants if also a fabric
administrator.
Built-in administrator credentials are
specied when conguring single
sign-on.
IaaS Administrator
n
Congure IaaS features, global properties.
n
Create and manage fabric groups.
n
Create and manage endpoints.
n
Manage endpoint credentials.
n
Congure proxy agents.
n
Manage Amazon AWS instance types.
n
Monitor IaaS-specic logs.
n
Create and manage (view, edit, and delete)
reservations across tenants if also a fabric
administrator.
The system administrator designates
the IaaS administrator when
conguring a tenant.
Foundations and Concepts
16 VMware, Inc.