Administration

Table Of Contents
Configuring Role-Based Delegated
Administration 4
One key management task in a View environment is to determine who can use View Administrator and
what tasks those users are authorized to perform. With role-based delegated administration, you can
selectively assign administrative rights by assigning administrator roles to specific Active Directory users
and groups.
This chapter includes the following topics:
n
“Understanding Roles and Privileges,” on page 63
n
“Using Access Groups to Delegate Administration of Pools and Farms,” on page 64
n
“Understanding Permissions,” on page 65
n
“Manage Administrators,” on page 66
n
“Manage and Review Permissions,” on page 67
n
“Manage and Review Access Groups,” on page 69
n
“Manage Custom Roles,” on page 71
n
“Predefined Roles and Privileges,” on page 73
n
“Required Privileges for Common Tasks,” on page 77
n
“Best Practices for Administrator Users and Groups,” on page 79
Understanding Roles and Privileges
The ability to perform tasks in View Administrator is governed by an access control system that consists of
administrator roles and privileges. This system is similar to the vCenter Server access control system.
An administrator role is a collection of privileges. Privileges grant the ability to perform specific actions,
such as entitling a user to a desktop pool. Privileges also control what an administrator can see in View
Administrator. For example, if an administrator does not have privileges to view or modify global policies,
the Global Policies setting is not visible in the navigation panel when the administrator logs in to View
Administrator.
Administrator privileges are either global or object-specific. Global privileges control system-wide
operations, such as viewing and changing global settings. Object-specific privileges control operations on
specific types of objects.
Administrator roles typically combine all of the individual privileges required to perform a higher-level
administration task. View Administrator includes predefined roles that contain the privileges required to
perform common administration tasks. You can assign these predefined roles to your administrator users
and groups, or you can create your own roles by combining selected privileges. You cannot modify the
predefined roles.
VMware, Inc.
63