VMware 4817V62 Administration Guide - Page 212

Default Roles for ESX/ESXi and vCenter Server, System roles, Sample roles, Table 18-1.

Page 212 highlights

vSphere Basic System Administration The roles created on an ESX/ESXi host are separate from the roles created on a vCenter Server system. When you manage a host using vCenter Server, only the roles created through vCenter Server are available. If you connect directly to the host using the vSphere Client, only the roles created directly on the host are available. vCenter Server and ESX/ESXi hosts provide default roles: System roles Sample roles System roles are permanent. You cannot edit the privileges associated with these roles. VMware provides sample roles for convenience as guidelines and suggestions. You can modify or remove these roles. You can also create completely new roles. All roles permit the user to schedule tasks by default. Users can schedule only tasks they have permission to perform at the time the tasks are created. NOTE Changes to permissions and roles take effect immediately, even if the users involved are logged in, except for searches, where permissions changes take effect after the user has logged out and logged back in again. Default Roles for ESX/ESXi and vCenter Server vCenter Server, ESX, and ESXi provide default roles. These roles group together privileges for common areas of responsibility in a vSphere environment. You can use the default roles to assign permissions in your environment, or use them as a model to develop your own roles. Table 18-1 lists the default roles for ESX/ESXi and vCenter Server. Table 18-1. Default Roles Role Role Type Description of User Capabilities No Access system Read Only system Administrator system Virtual Machine Power User sample Cannot view or change the assigned object. vSphere Client tabs associated with an object appear without content. This role can be used to revoke permissions that would otherwise be propagated to an object from a parent object. This role is available in ESX/ESXi and vCenter Server. View the state and details about the object. View all the tab panels in the vSphere Client except the Console tab. Cannot perform any actions through the menus and toolbars. This role is available on ESX/ESXi and vCenter Server. All privileges for all objects. Add, remove, and set access rights and privileges for all the vCenter Server users and all the virtual objects in the vSphere environment. This role is available in ESX/ESXi and vCenter Server. A set of privileges to allow the user to interact with and make hardware changes to virtual machines, as well as perform snapshot operations. Privileges granted include: n All privileges for the scheduled task privileges group. n Selected privileges for global items, datastore, and virtual machine privileges groups. n No privileges for folder, datacenter, network, host, resource, alarms, sessions, performance, and permissions privileges groups. Usually granted on a folder that contains virtual machines or on individual virtual machines. This role is available only on vCenter Server. 212 VMware, Inc.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364

The roles created on an ESX/ESXi host are separate from the roles created on a vCenter Server system. When
you manage a host using vCenter Server, only the roles created through vCenter Server are available. If you
connect directly to the host using the vSphere Client, only the roles created directly on the host are available.
vCenter Server and ESX/ESXi hosts provide default roles:
System roles
System roles are permanent. You cannot edit the privileges associated with
these roles.
Sample roles
VMware provides sample roles for convenience as guidelines and suggestions.
You can modify or remove these roles.
You can also create completely new roles.
All roles permit the user to schedule tasks by default. Users can schedule only tasks they have permission to
perform at the time the tasks are created.
N
OTE
Changes to permissions and roles take effect immediately, even if the users involved are logged in,
except for searches, where permissions changes take effect after the user has logged out and logged back in
again.
Default Roles for ESX/ESXi and vCenter Server
vCenter Server, ESX, and ESXi provide default roles. These roles group together privileges for common areas
of responsibility in a vSphere environment.
You can use the default roles to assign permissions in your environment, or use them as a model to develop
your own roles.
Table 18-1
lists the default roles for ESX/ESXi and vCenter Server.
Table 18-1.
Default Roles
Role
Role Type
Description of User Capabilities
No Access
system
Cannot view or change the assigned object.
vSphere Client tabs associated with an object appear without content.
This role can be used to revoke permissions that would otherwise be
propagated to an object from a parent object.
This role is available in ESX/ESXi and vCenter Server.
Read Only
system
View the state and details about the object.
View all the tab panels in the vSphere Client except the Console tab.
Cannot perform any actions through the menus and toolbars.
This role is available on ESX/ESXi and vCenter Server.
Administrator
system
All privileges for all objects.
Add, remove, and set access rights and privileges for all the vCenter
Server users and all the virtual objects in the vSphere environment.
This role is available in ESX/ESXi and vCenter Server.
Virtual Machine Power
User
sample
A set of privileges to allow the user to interact with and make hardware
changes to virtual machines, as well as perform snapshot operations.
Privileges granted include:
n
All privileges for the scheduled task privileges group.
n
Selected privileges for global items, datastore, and virtual machine
privileges groups.
n
No privileges for folder, datacenter, network, host, resource, alarms,
sessions, performance, and permissions privileges groups.
Usually granted on a folder that contains virtual machines or on
individual virtual machines.
This role is available only on vCenter Server.
vSphere Basic System Administration
212
VMware, Inc.