5.1

Table Of Contents
5 Type the vCenter User name for the user.
NOTE If the vCenter user is from a domain (such as a SSO user), then you must enter a fully qualified
windows domain path. This will allow the default vShield Manager user (admin) as well as the SSO default
user (admin) to login to vShield Manager. This user name is for login to the vShield Manager user interface,
and cannot be used to access the vShield App or vShield Manager CLIs.
6 Click Next.
7 Select the role for the user and click Next. For more information on the available roles, see “Managing
User Rights,” on page 32.
8 Select the scope for the user and click Finish.
The user account appears in the Users table.
Understanding Group Based Role Assignments
Organizations create user groups for proper user management. After integration with Single Sign On (SSO),
vShield Manager can get the details of groups to which a user belongs to. Instead of assigning roles to individual
users who may belong to the same group, vShield Manager assigns roles to groups. Let us walk through some
scenarios to help us understand how vShield Manager assigns roles.
Example: Scenario 1
Group option Value
Name G1
Role assigned Auditor (Read only)
Resources Global root
User option Value
Name John
Belongs to group G1
Role assigned None
John belongs to group G1 which has been assigned the auditor role. John inherits the group role and resource
permissions.
Example: Scenario 2
Group option Value
Name G1
Role assigned Auditor (Read only)
Resources Global root
Group option Value
Name G2
Role assigned Security Administrator (Read and Write)
Resources Datacenter1
vShield Administration Guide
34 VMware, Inc.