Table 18-1.
Default Roles (Continued)
Role
Role Type
Description of User Capabilities
Virtual Machine User
sample
A set of privileges to allow the user to interact with a virtual machine’s
console, insert media, and perform power operations. Does not grant
privileges to make virtual hardware changes to the virtual machine.
Privileges granted include:
n
All privileges for the scheduled tasks privileges group.
n
Selected privileges for the global items and virtual machine
privileges groups.
n
No privileges for the folder, datacenter, datastore, network, host,
resource, alarms, sessions, performance, and permissions privileges
groups.
Usually granted on a folder that contains virtual machines or on
individual virtual machines.
This role is available only on vCenter Server.
Resource Pool
Administrator
sample
A set of privileges to allow the user to create child resource pools and
modify the configuration of the children, but not to modify the resource
configuration of the pool or cluster on which the role was granted. Also
allows the user to grant permissions to child resource pools, and assign
virtual machines to the parent or child resource pools.
Privileges granted include:
n
All privileges for folder, virtual machine, alarms, and scheduled
task privileges groups.
n
Selected privileges for resource and permissions privileges groups.
n
No privileges for datacenter, network, host, sessions, or
performance privileges groups.
Additional privileges must be granted on virtual machines and
datastores to allow provisioning of new virtual machines.
Usually granted on a cluster or resource pool.
This role is available only on vCenter Server.
VMware Consolidated
Backup User
sample
This role is designed for use by the VMware Consolidated Backup
product and should not be modified.
This role is available only on vCenter Server.
Datastore Consumer
sample
A set of privileges to allow the user to consume space on the datastores
on which this role is granted. To perform a space-consuming operation,
such as creating a virtual disk or taking a snapshot, the user must also
have the appropriate virtual machine privileges granted for these
operations.
Usually granted on a datastore or a folder of datastores.
This role is available only on vCenter Server.
Network Consumer
sample
A set of privileges to allow the user to assign virtual machines or hosts
to networks, provided that the appropriate permissions for the
assignment are also granted on the virtual machines or hosts.
Usually granted on a network or folder of networks.
This role is available only on vCenter Server.
Create a Role
VMware recommends that you create roles to suit the access control needs of your environment.
If you create or edit a role on a vCenter Server system that is part of a connected group in Linked Mode, the
changes you make are propagated to all other vCenter Server systems in the group. Assignments of roles to
specific users and objects are not shared across linked vCenter Server systems.
Prerequisites
You must be logged in as a user with Administrator privileges.
Chapter 18 Managing Users, Groups, Roles, and Permissions
VMware, Inc.
213
Summary of Contents for 4817V62 - vSphere - PC
Page 13: ...Getting Started VMware Inc 13...
Page 14: ...vSphere Basic System Administration 14 VMware Inc...
Page 24: ...vSphere Basic System Administration 24 VMware Inc...
Page 38: ...vSphere Basic System Administration 38 VMware Inc...
Page 76: ...vSphere Basic System Administration 76 VMware Inc...
Page 85: ...Virtual Machine Management VMware Inc 85...
Page 86: ...vSphere Basic System Administration 86 VMware Inc...
Page 98: ...vSphere Basic System Administration 98 VMware Inc...
Page 131: ...3 Click OK Chapter 11 Creating Virtual Machines VMware Inc 131...
Page 132: ...vSphere Basic System Administration 132 VMware Inc...
Page 140: ...vSphere Basic System Administration 140 VMware Inc...
Page 172: ...vSphere Basic System Administration 172 VMware Inc...
Page 182: ...vSphere Basic System Administration 182 VMware Inc...
Page 200: ...vSphere Basic System Administration 200 VMware Inc...
Page 207: ...System Administration VMware Inc 207...
Page 208: ...vSphere Basic System Administration 208 VMware Inc...
Page 278: ...vSphere Basic System Administration 278 VMware Inc...
Page 289: ...Appendixes VMware Inc 289...
Page 290: ...vSphere Basic System Administration 290 VMware Inc...
Page 324: ...vSphere Basic System Administration 324 VMware Inc...
Page 364: ...vSphere Basic System Administration 364 VMware Inc...