VMware Cloud Community
quantum_2
Enthusiast
Enthusiast

VCAC 6.0 does the tenant administrator rights include all the tenant infrastructre rights a well

Is there any reason to add a user to the infrastructure admin for the tenant if he has already been added to the tenant INFRASTRUCTURE admin ?

thanks

0 Kudos
3 Replies
admin
Immortal
Immortal

There are differences between the two. Here's some outlines of the differences for you:

- Tenant administrators can manage:

Everything under Administration tab

Under the Infrastructure tab:

Recent Events

Machines/Reserved Machines

Groups/Business Groups

Blueprints/Blueprints

Blueprints/Build Profiles

Blueprints/Prop Dictionary

- Infrastructure administrators can manage:

Nothing under the Administration tab!

Under the Infrastructure tab:

Groups/Fabric Groups

Endpoints/*

Administration/*

Monitoring/*

So there are differences and there is a difference in what you see if you are a fabric administrator.

Oli

0 Kudos
quantum_2
Enthusiast
Enthusiast

thanks for the reply , so If I want to give someone the "keys to the kingdom" I would add them to fabric admin , tenant admin , infra admin and user role . this would give them access to every thing?

thanks

0 Kudos
admin
Immortal
Immortal

That would give them most things in vcac, but I would add that user as a business group manager to all business groups and add them as a service architect to give them the ASD authoring role. Also, I think instead adding the user to these roles, add a group to each role and place the user in the group. The group can be an AD from SSO identity source or local custom group in vCAC. The reason you need the business group manager role is to manage catalogue items, do actions on behalf of users manage inboxes and requests

Have a look at the attached and this link -

http://grantorchard.com/vcac/concepts/visual-guide-vcac-permissions/

Hope that helps

Oli

0 Kudos