vmrulz
Hot Shot
Hot Shot

vCenter 6.7u1 global perms?

Hello,

We have a 6.7u1 with embedded PSC serving some VDI clusters. We've noticed that even though we place global groups in global permissions with the same role as administrator@vsphere.local the users do not have the same elevated permissions that account does. That appears to be  change from prior vCenter versions. Anybody know how to change this behavior?

Thanks,

Ron

0 Kudos
4 Replies
daphnissov
Immortal
Immortal

What are you finding are lacking in the way of permissions compared to the default SSO administrator account?

0 Kudos
vmrulz
Hot Shot
Hot Shot

Hi,

I said all that and now I'm not seeing any differences. We started off not putting admin groups in global perms but rather in the old fashioned vcenter hosts/clusters view from top down and found issues as I describe.. however I don't seem to be seeing any difference now with using global perms as one would expect.

Egg on face.

0 Kudos
daphnissov
Immortal
Immortal

And you shouldn't because if you don't have linked vCenters, there's no difference between granting a role access at the root vCenter level versus global permission sets.

0 Kudos
Raj1988
Enthusiast
Enthusiast

If you want to give domain users/groups similar to SSO admin user ; do the below. This has been similar across versions .

https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.psc.doc/GUID-CDEA6F32-7581-4615-8572-E0B44C...

0 Kudos