VMware Cloud Community
oschroeder8
Contributor
Contributor

Assigning global permissions using PowerCLI

When setting up a vCenter 6u1 instance on Windows Server 2012 R2 and connecting to the vCenter as the SSO administrative account (administrator@vsphere.local) via PowerCLI, I do not seem to be able to configure any local user accounts with global permissions.

I have tried using New-VIPermission but the highest entity I can assign roles/users to is Datacenters, i.e. the root of the vCenter inventory tree, so to speak. I want to make it so that all local Windows user accounts that are part of the Administrators group are also SSO admins. Via the vCenter web client I can only make changes to the SSO stuff when logging in as the SSO admin but then I can add the local Administrators group to the global permissions section with the Admin role and after that any local administrative user logging on does have permission to make SSO changes. So it is possible to do via web client, but how can I do it via PowerCLI?

Tags (1)
4 Replies
oschroeder8
Contributor
Contributor

What?!?! No takers?

I did get Onyx running in vCenter 6 u1 with the recent update but Onyx does not capture anything in the Administration section it would seem.

Anyone have any idea how to do this?

0 Kudos
LucD
Leadership
Leadership

Afaik there are no PiwerCLI cmdlets for that, not even sure if SSO offers public API.

But you can use the rsautil command, that you can find in %ProgramFiles%\VMware\Infrastructure\SSOServer\utils


Blog: lucd.info  Twitter: @LucD22  Co-author PowerCLI Reference

oschroeder8
Contributor
Contributor

LucD,

Thanks for the reply. I will look into that. Maybe that utility or another, related one can do this. I will update this thread if I find out how. (I am specifically trying to add the local Administrators group to the vShpere.local Administrators group, rsautil does not seem to be able to do that.)

0 Kudos
LucD
Leadership
Leadership

Are you sure that will work.

Afaik the users you add need to belong to AD or OpenLDAP groups.


Blog: lucd.info  Twitter: @LucD22  Co-author PowerCLI Reference

0 Kudos