Administration

Table Of Contents
Table 414. Privileges for General Administration Tasks and Commands (Continued)
Task Required Privileges
Use the vdmadmin and vdmimport commands
Must have the Administrators role on the root access
group.
Use the vdmexport command
Must have the Administrators role or the Administrators
(Read only) role on the root access group.
Best Practices for Administrator Users and Groups
To increase the security and manageability of your View environment, you should follow best practices
when managing administrator users and groups.
n
Create new user groups in Active Directory and assign View administrative roles to these groups.
Avoid using Windows built-in groups or other existing groups that might contain users who do not
need or should not have View privileges.
n
Keep the number of users with View administrative privileges to a minimum.
n
Because the Administrators role has every privilege, it should not be used for day-to-day
administration.
n
Because it is highly visible and easily guessed, avoid using the name Administrator when creating
administrator users and groups.
n
Create access groups to segregate sensitive desktops and farms. Delegate the administration of those
access groups to a limited set of users.
n
Create separate administrators that can modify global policies and View configuration settings.
Chapter 4 Configuring Role-Based Delegated Administration
VMware, Inc. 79