6.3

Table Of Contents
n
vRealize Operations General User Role 2
n
vRealize Operations General User Role 3
n
vRealize Operations General User Role 4
n
vRealize Operations Power User Role
n
vRealize Operations Power User without Remediation Actions Role
n
vRealize Operations Read Only Role
For more information about vCenter Server users, groups, and roles, see the vCenter Server documentation.
External User Sources in vRealize Operations Manager
You can obtain user accounts from external sources so that you can use them in your
vRealize Operations Manager instance.
There are two types of external user identity sources:
n
Lightweight Directory Access Protocol (LDAP): Use the LDAP source if you want to use the Active
Directory or LDAP servers as authentication sources. The LDAP source does not support multi-
domains even when there is a two-way trust between Domain A and Domain B.
n
Single Sign-On (SSO): Use a single sign-on source to perform single sign-on with any application that
supports vCenter single sign-on, including vRealize Operations Manager. For example, you can install a
standalone vCenter Platform Services Controller (PSC) and use it to communicate with an Active
Directory server. Use a PSC if the Active Directory has a setup that is too complex for the simple LDAP
source in vRealize Operations Manager, or if the LDAP source is experiencing slow performance. If
your PSC is congured to use Active Directory with integrated Windows authentication mode, SSO
users can log in using Windows authentication.
Roles and Privileges in vRealize Operations Manager
vRealize Operations Manager provides several predened roles to assign privileges to users. You can also
create your own roles.
You must have privileges to access specic features in the vRealize Operations Manager user interface. The
roles associated with your user account determine the features you can access and the actions you can
perform.
Each predened role includes a set of privileges for users to perform create, read, update, or delete actions
on components such as dashboards, reports, administration, capacity, policies, problems, symptoms, alerts,
user account management, and adapters.
Administrator
Includes privileges to all features, objects, and actions in
vRealize Operations Manager.
ReadOnly
Users have read-only access and can perform read operations, but cannot
perform write actions such as create, update, or delete.
PowerUser
Users have privileges to perform the actions of the Administrator role except
for privileges to user management and cluster management.
vRealize Operations Manager maps vCenter Server users to this role.
PowerUserMinusRemed
iation
Users have privileges to perform the actions of the Administrator role except
for privileges to user management, cluster management, and remediation
actions.
ContentAdmin
Users can manage all content, including views, reports, dashboards, and
custom groups in vRealize Operations Manager
Chapter 1 Configuring Users and Groups in vRealize Operations Manager
VMware, Inc. 13