The security chap has asked me to investigate if the service account for View can have anything less than Administrator permissions at the root of the vCenter heirarchy.
Has anyone tried reducing the rights of the service account successfully?
We will have dedicated hosts (in a dedicated cluster) for VDI so is it just a case of:
1. Giving the account admin permissions at the level of the Inventory folder (VMs and Templates view) where the VMs will go
2. Giving the accoun admin permissions at the VDI cluster level
?
We are not using Composer, so that simplifies things a bit.
I'm going to give this a try today but would be interested if anyone else has done something similar.
Thanks
Chris