6.3

Table Of Contents
GeneralUser-1 through
GeneralUser-4
These predened template roles are initially dened as ReadOnly roles.
vCenter Server administrators can congure these roles to create
combinations of roles to give users multiple types of privileges. Roles are
synchronized to vCenter Server once during registration.
AgentManager
Users can deploy and congure Endpoint Operations Management agents.
User Scenario: Manage User Access Control
As a system administrator or virtual infrastructure administrator, you manage user access control in
vRealize Operations Manager so that you can ensure the security of your objects. Your company just hired a
new person, and you must create a user account and assign a role to the account so that the new user has
permission to access specic content and objects in vRealize Operations Manager.
In this scenario you will learn how to create user accounts and roles, and assign roles to the user accounts to
specify access privileges to views and objects. You will then demonstrate the intended behavior of the
permissions on these accounts.
You will create a new user account, named Tom User, and a new role that grants administrative access to
objects in the vRealize Operations Clusters. You will apply the new role to the user account.
Finally, you will import a user account from an external LDAP user database that resides on another
machine to vRealize Operations Manager, and assign a role to the imported user account to congure the
user's privileges.
Prerequisites
Verify that the following conditions are met:
n
vRealize Operations Manager is installed and operating properly, and contains objects such as clusters,
hosts, and virtual machines.
n
One or more user groups are dened.
Procedure
1 Create a New Role on page 14
You use roles to manage access control for user accounts in vRealize Operations Manager.
2 Create a User Account on page 15
As an administrator you assign a unique user account to each user so that they can use
vRealize Operations Manager. While you set up the user account, you assign the privileges that
determine what activities the user can perform in the environment, and upon what objects.
3 Import a User Account and Assign Permissions on page 16
You can import user accounts from external sources, such as an LDAP database on another machine,
or a single sign-on server, so that you can give permission to those users to access certain features and
objects in vRealize Operations Manager.
What to do next
Create a new role.
Create a New Role
You use roles to manage access control for user accounts in vRealize Operations Manager.
In this procedure, you will add a new role and assign administrative permissions to the role.
vRealize Operations Manager Customization and Administration Guide
14 VMware, Inc.