VMware Cloud Community
Ahmed_Naguib
Contributor
Contributor

How to prevent a business group admin from creating blueprints

     Hello,

Is there a way where I can limit the business group admin from creating blueprints ?

We need to allow him only to deploying machines, and manage machines deployed by users under his business group.

We are using VCAC 6.1.1

There should be a role that we remove from the admin to achieve that, however I am not sure which one it should be.

Anyone came across a similar situation ?

0 Kudos
3 Replies
SeanKohler
Expert
Expert


>>We need to allow him only to deploying machines, and manage machines deployed by users under his business group.

These come from Entitlements to Services, Catalog Items, and Resource Actions.

>>Is there a way where I can limit the business group admin from creating blueprints ?

I think you mean the Group Manager Role?

User, Support User, and Group Manager provide access to see machines in the Business Group.

  • User can only see their machines.
  • Support User can see all machines.
  • Group Manager can see all machines.

Entitlement determines provisioning and actions.

Business Group Manager gives a lot of other permissions outside of just interacting with published catalog items and deployed machines. User doesn't allow for seeing other machines in the business group.

So for us... we just went with Support User across the board for ACCESS to the business group and divided our community into Entitlement roles (because you can have multiple entitlements per business group) and each role has different entitlements.  Like some can provision with catalog items... and some can only work with provisioned machines.

There are others out there that are using a very different use case where business groups are handed over fully to another group... and they can build up their own blueprints.  That wasn't our use case for now... and it sounds like it also isn't your use case.

I would suggest you look at putting all your AD usergroups, or AD users, in the Support Users group.  I think it will do what you need.

0 Kudos
GrantOrchardVMw
Commander
Commander

Yes. Sean has hit the nail on the head. Assign the Support User role, as there is no way to limit the Business Group Manager permissions. Then assign the Business Group Manager role to a different account that only system administrators have access to.

Grant

Grant http://grantorchard.com
0 Kudos
Ahmed_Naguib
Contributor
Contributor

Thank you Gents for your feedback..

I will try to use the support role instead of admin role in the lab, and see if it fits our use case as expected.

Thanks very much.

Regards

Ahmed

0 Kudos