6.3

Table Of Contents
Refreshing Permissions
When you change permissions for a vCenter Server user in vCenter Server, the user must log out and log
back in to vRealize Operations Manager to refresh the permissions and view the updated results in
vRealize Operations Manager. Alternatively, the user can wait for vRealize Operations Manager to refresh.
The permissions refresh at xed intervals, as dened in the $ALIVE_BASE/user/conf/auth.properties le.
The default refreshing interval is half an hour. If necessary, you can change this interval for all nodes in the
cluster.
Single Sign-On and vCenter Users
When vCenter Server users log into vRealize Operations Manager by way of single sign-on, they are
registered on the vRealize Operations Manager User Accounts page. If you delete the account of a
vCenter Server user that has logged into vRealize Operations Manager by way of single sign-on, or remove
the user from a single sign-on group, the user account entry still appears on the User Account page and you
must delete it manually.
Generating Reports
vCenter Server users cannot create or schedule reports in vRealize Operations Manager.
Backward Compatibility for vCenter Server Users in vRealize Operations Manager
vRealize Operations Manager provides backward compatibility for users of the earlier version of
vRealize Operations Manager, so that users of vCenter Server who have privileges in the earlier version in
vCenter Server can log in to vRealize Operations Manager.
When you register vRealize Operations Manager in vCenter Server, certain roles become available in
vCenter Server.
n
The Administrator account in the previous version of vRealize Operations Manager maps to the
PowerUser role.
n
The Operator account in the previous version of vRealize Operations Manager maps to the ReadOnly
role.
During registration, all roles in vRealize Operations Manager, except for vRealize Operations Manager
Administrator, Maintenance, and Migration, become available dynamically in vCenter Server.
Administrators in vCenter Server have all of the roles in vRealize Operations Manager that map during
registration, but these administrator accounts only receive a specic role on the root folder in vCenter Server
if it is specially assigned.
Registration of vRealize Operations Manager with vCenter Server is optional. If users choose not to register
vRealize Operations Manager with vCenter Server, a vCenter Server administrator can still use their user
name and password to log in to vRealize Operations Manager, but these users cannot use the vCenter Server
session ID to log in. In this case, typical vCenter Server users must have one or more
vRealize Operations Manager roles to log in to vRealize Operations Manager.
When multiple instances of vCenter Server are added to vRealize Operations Manager, user credentials
become valid for all of the vCenter Server instances. When a user logs in to vRealize Operations Manager, if
the user selects all vCenter Server options during login, vRealize Operations Manager requires that the
user's credentials are valid for all of the vCenter Server instances. If a user account is only valid for a single
vCenter Server instance, that user can select the vCenter Server instance from the login drop-down menu to
log in to vRealize Operations Manager.
vCenter Server users who log in to vRealize Operations Manager must have one or more of the following
roles in vCenter Server:
n
vRealize Operations Content Admin Role
n
vRealize Operations General User Role 1
vRealize Operations Manager Customization and Administration Guide
12 VMware, Inc.