VMware Cloud Community
sgentzen
Contributor
Contributor

Using roles to restrict access to certain VM's?

I've been digging through the Roles section of VC and the appendix in the basic administration guide and I haven't been able to find what I'm looking for.

It seems that most of the role permissions have to do with delegating certain administration tasks across the entire virtual infrastructure. I'm looking to do something a little different...

I'm working on doing some hosting of other organizations' systems in my infrastructure. I want the system owners to be able to access their systems via the VC client (since sometimes RDP isn't good enough), but not have access to systems that aren't theirs. At the moment, I have system owners that I mostly trust in the system to admin their stuff without doing anything that would make a mess but that might not be true in the future.

Is something like this there that I missed? Or is it not there at all? Or am I looking at this the wrong way?

0 Kudos
3 Replies
Dave_Mishchenko
Immortal
Immortal

You can assign permissions on most object in the VC structure so if you look at a VM for example, you'll see the permissions tab and you can then add a user / goup with a specific role to that VM alone. You can then have them access it with the web client and they'll just see that VM. If you goup a set of VMs into a resource pool, you can also assign permissions to the resource pool so that a user or group can manage all VMs in that pool.

0 Kudos
rriva
Expert
Expert

Seems that you want that other people eill be administrator of their VM and can't see anything else on you r infrastructure .... is'nt that ?

In this case you can create a user (on your Windows Virtual Center Host or in your Active Directory as you prefer), set to this user the "VM Administrator" to one or more VM and set "No Access" to this user to all you infrastructure.

Doig this, the user you've just created can login to your Virtual Center using Virtual Infrastructure Client, but the only thing that will see is his VM.

Hoping understand what you've asked ...

RRiva | http://about.me/riccardoriva | http://www.riccardoriva.com
0 Kudos
jandie
Enthusiast
Enthusiast

Hi,

I don't know if the question's been answered or not but your situation is almost the same as ours. We created folders under the Virtual Machines and Templates view and created a new role for those folders. For example, I created a Linux folder and only assign Linux Admins to be able to access that folder ONLY. I created a role called Linux VM Admins that has only: Global - Cancel Task, Virtual Machine - Interaction - Console interation, etc (you can build this to what you need). Anyways the gist here is to make a role that fits to the needs of each company and only assign that role to users that you want to the specific folders. So in my example, the Linux admins can't interact nor see the windows folder/vm. Don't know if that's what you are looking for, but I hope it helps.

Have a great day,

jandie

0 Kudos