HP Matrix Operating Environment 7.3 and 7.3 Update 1 Infrastructure Orchestration User Guide

The designer enables an architect to plan and design multi-server, multi-tier infrastructures
using a drag-and-drop interface.
The console enables a service provider administrator to deploy, manage, and monitor the
overall behavior of infrastructure orchestration and its users, templates, services, and resources.
The organization administrator portal enables an organization administrator to deploy, manage
and monitor the behavior of an individual infrastructure orchestration organization and its
users, templates, services, and resources.
The self service portal enables a user to create infrastructure services from published templates.
Matrix infrastructure orchestration users and groups
Matrix infrastructure orchestration is integrated with Active Directory, which allows Windows users
groups, as well as individual local users, to be given access to resources. When infrastructure
orchestration is installed, three local user groups (HPIO_Administrators, HPIO_Architects, and
HPIO_Users) are created.
The Windows CMS administrator populates the service provider roles by adding local Windows
users and Active Directory users or groups to HPIO_Administrators, HPIO_Architects, and
HPIO_Users. When an organization is created, two local Windows groups are created with
descriptions indicating the organization’s name. These local groups have names of the form
<organization_id>_Administrators and <organization_id>_Users.
Users can belong to more than one IO Windows group and therefore belong to multiple IO
organizations. Such users can be simultaneously logged in to one or more of the organization
administrator portals belonging to different organizations. If a user is removed from an organization,
the removal takes effect after the user logs out from the organization administrator portal.
A group of users (for example, an Active Directory group) can be authorized to view and perform
lifecycle operations in the same way that users are authorized. For example, a user who is part
of a group can view server pools assigned to a group, assign a group to a server pool, and view
templates assigned to a group. Server pools can be assigned to one or more groups.
A user in a group is authorized based on the group's assignment to an IO role. A change in a
user's group reflects new group assignments on the next login by the user to infrastructure
orchestration.
Matrix infrastructure orchestration users and groups 13