Lab-17-user Permissions

Giving access to a user helps in reviewing the console he can perform few actions but can not do all the major modifications

In this lab, I am going to

1)Create a Custom Role in vCenter Server

2)Assign Permissions on vCenter Server Inventory Objects

3)Verify Permission Usability

open the web client by the url “https://vcenter.deepak.local:9443/vsphere-client/#”  login by giving the credentials

Create a Custom Role in vCenter Server

here in this task i opened the  vcenter then Administration then Roles and started the wizard to create a new roleScreenshot (1972)

For the ‘Role Name’, I entered ‘VM Creator-deepak’

I then specified a variety of privileges that the  users  can assigned this role and  will be able to carry out. These include the following

Datastore >Allocate space

Network -> Assign network

Resource -> Assign virtual machine to resource pool

Virtual Machine -> Configuration

Add new disk

Add or remove device

Memory

Virtual Machine -> Interaction -> All settings

Virtual Machine -> Inventory -> Create new

Screenshot (1973)

Assigning Permissions on vCenter Server Inventory Objects

We can add permissions for each and every item in host and cluster list. This action is done for this i opened the  hosts and clusters in vcenter i expanded the  Lab servers folder and gone to Mange then to Permissions . I clicked on Add Permission ‘+’ sign in the dashboard at the upper side

Screenshot (1975)

i have chosen the previlages from here and i have used

Screenshot (1979)

Screenshot (1982)

here i can see the selected user

17th1

these are the permissions i have assigned

17th2

i logged out and again logged in by the user name ‘firstdeepak’ as i have assigned the roles and permissions we can see at the corner along with the domain name

17th3

Conclusion:

here by assigning the roles and permissions we can access the talos console by this it makes our work easier in many aspects like configuring , viewing , setting the modifications and so on

all this things are enabled as the user along with domain has given certain permissions