5.1

Table Of Contents
2 Click the Configuration tab.
3 Ensure that you are in the General tab.
4 Click Edit next to Lookup Service.
5 Type the name or IP address of the host that has the lookup service.
6 Change the port number if required.
The Lookup Service URL is displayed based on the specified host and port.
7 Type the SSO user name and password.
This enables vShield Manager to register itself with the Security Token Service server.
8 Click OK.
What to do next
Assign a role to the SSO user.
Managing User Rights
Within the vShield Manager user interface, a user’s role define the actions the user is allowed to perform on a
given resource. The role determine the user’s authorized activities on the given resource, ensuring that a user
has access only to the functions necessary to complete applicable operations. This allows domain control over
specific resources, or system-wide control if your right has no restrictions.
The following rules are enforced:
n
A user can only have one role.
n
You cannot add a role to a user, or remove an assigned role from a user. You can, however, change the
assigned role for a user.
Table 4-1. vShield Manager User Roles
Right Permissions
Enterprise Administrator vShield operations and security.
vShield Administrator vShield operations only: for example, install virtual appliances, configure port groups.
Security Administrator vShield security only: for example, define data security policies, create port groups, create
reports for vShield modules.
Auditor Read only.
The scope of a role determines what resources a particular user can view. The following scopes are available
for vShield users.
Table 4-2. vShield Manager User Scope
Scope Description
No restriction Access to entire vShield system
Limit access scope to the
selected port groups below
Access to a specified datacenter or port group
The Enterprise Administrator and vShield Administrator roles can only be assigned to vCenter users, and their
access scope is global (no restrictions).
vShield Administration Guide
32 VMware, Inc.