VMware 4817V62 Administration Guide - Page 221

Adjust the Search List in Large Domains, Change Permission Validation Settings, Change Permissions

Page 221 highlights

Chapter 18 Managing Users, Groups, Roles, and Permissions Adjust the Search List in Large Domains If you have domains with thousands of users or groups, or if searches take a long time to complete, adjust the search settings for use in the Select Users or Groups dialog box. NOTE This procedure applies only to vCenter Server user lists. ESX/ESXi user lists cannot be searched in the same way. Procedure 1 From the vSphere Client connected to a vCenter Server system, select Administration > vCenter Server Management Server Configuration. 2 Click the Active Directory list item. 3 Change the values as needed. Option Active Directory Timeout Enable Query Limit Users & Groups value Description Specifies in seconds the maximum amount of time vCenter Server allows the search to run on the selected domain. Searching very large domains can take a very long time. To specify no maximum limit on the number of users and groups that vCenter Server displays from the selected domain, deselect the check box. Specifies the maximum number of users and groups vCenter Server displays from the selected domain in the Select Users or Groups dialog box. 4 Click OK. Change Permission Validation Settings vCenter Server periodically validates its user and group lists against the users and groups in the Windows Active Directory domain, and removes users or groups that no longer exist in the domain. You can change the interval between validations. Procedure 1 From the vSphere Client connected to a vCenter Server system, select Administration > vCenter Server Management Server Configuration. 2 Click the Active Directory list item. 3 Deselect the Enable Validation check box to disable validation. Validation is enabled by default. Users and groups are always validated when vCenter Server system starts, even if validation is disabled. 4 If validation is enabled, enter a value in the Validation Period text box to specify a time, in minutes, between validations. Change Permissions After a user or group and role pair is set for an inventory object, you can change the role paired with the user or group or change the setting of the Propagate check box. You can also remove the permission setting. Procedure 1 From the vSphere Client, select an object in the inventory. 2 Click the Permissions tab. 3 Click the line item to select the user or group and role pair. VMware, Inc. 221

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364

Adjust the Search List in Large Domains
If you have domains with thousands of users or groups, or if searches take a long time to complete, adjust the
search settings for use in the Select Users or Groups dialog box.
N
OTE
This procedure applies only to vCenter Server user lists. ESX/ESXi user lists cannot be searched in the
same way.
Procedure
1
From the vSphere Client connected to a vCenter Server system, select
Administration > vCenter Server
Management Server Configuration
.
2
Click the
Active Directory
list item.
3
Change the values as needed.
Option
Description
Active Directory Timeout
Specifies in seconds the maximum amount of time vCenter Server allows the
search to run on the selected domain. Searching very large domains can take
a very long time.
Enable Query Limit
To specify no maximum limit on the number of users and groups that
vCenter Server displays from the selected domain, deselect the check box.
Users & Groups value
Specifies the maximum number of users and groups vCenter Server displays
from the selected domain in the Select Users or Groups dialog box.
4
Click
OK
.
Change Permission Validation Settings
vCenter Server periodically validates its user and group lists against the users and groups in the Windows
Active Directory domain, and removes users or groups that no longer exist in the domain. You can change the
interval between validations.
Procedure
1
From the vSphere Client connected to a vCenter Server system, select
Administration > vCenter Server
Management Server Configuration
.
2
Click the
Active Directory
list item.
3
Deselect the
Enable Validation
check box to disable validation.
Validation is enabled by default. Users and groups are always validated when vCenter Server system
starts, even if validation is disabled.
4
If validation is enabled, enter a value in the
Validation Period
text box to specify a time, in minutes,
between validations.
Change Permissions
After a user or group and role pair is set for an inventory object, you can change the role paired with the user
or group or change the setting of the
Propagate
check box. You can also remove the permission setting.
Procedure
1
From the vSphere Client, select an object in the inventory.
2
Click the
Permissions
tab.
3
Click the line item to select the user or group and role pair.
Chapter 18 Managing Users, Groups, Roles, and Permissions
VMware, Inc.
221