This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
vmware:vcenter6_grant_access [2017/02/06 16:30] admin |
vmware:vcenter6_grant_access [2017/02/09 11:12] (current) admin |
||
---|---|---|---|
Line 21: | Line 21: | ||
To resolve this issue, assign permissions to the user attempting to access these new features: | To resolve this issue, assign permissions to the user attempting to access these new features: | ||
- | * To access the Single Sign-On Administration Section | + | * To access the **Single Sign-On** Administration Section |
- | - * Log in to the vSphere Web Client with the Administrator@vsphere.local | + | - Log in to the vSphere Web Client with the ''Administrator@vsphere.local'' |
- | - * Navigate to Administration > Single Sign-On > Users and Groups | + | - Navigate to **Administration** > **Single Sign-On** > **Users and Groups** |
- | - * Under vCenter Users and Groups, select the Groups tab | + | - Under vCenter **Users and Groups**, select the **Groups** tab |
- | - * Locate the Administrators Group | + | - Locate the **Administrators Group** |
- | - * Under Group Members, click Add member () icon | + | - Under **Group Members**, click **Add** member () icon |
- | - * In the Add Principals window, select the appropriate domain for your user under the Domain drop-down | + | - In the **Add Principals** window, select the appropriate domain for your user under the Domain drop-down |
- | - * Locate your user | + | - Locate your user |
+ | - ''Note: At this time, only users can use these permissions. For more information, see Unable to administer vCenter Single Sign-On after adding a User Group and individual users from a Directory Service (OpenLDAP or Active Directory) (2095342).'' | ||
+ | - Click **Add** | ||
+ | - Click **OK** | ||
- | ''Note: At this time, only users can use these permissions. For more information, see Unable to administer vCenter Single Sign-On after adding a User Group and individual users from a Directory Service (OpenLDAP or Active Directory) (2095342).'' | ||
- | - * Click Add | + | Once completed, log out of the vSphere Web Client and log in with your user account. Confirm you are able to access the **Users and Groups** and **Configuration** sections under **Single Sign-On**. |
- | - * Click OK | + | |
+ | * To access the **System Configuration** Section | ||
+ | Before you begin, ensure your user account has **Single Sign-On Administration** permissions. | ||
+ | - Log in to the **vSphere Web Client** with your user account or with the ''Administrator@vsphere.local'' | ||
+ | - Navigate to **Administration** > **Single Sign-On** > **Users and Groups** | ||
+ | - Under vCenter **Users and Groups**, select the **Groups** tab | ||
+ | - Locate the ''SystemConfiguration.Administrators Group'' | ||
+ | - Under **Group Members**, click the **Add** member () icon | ||
+ | - In the **Add Principals** window, select the appropriate domain for your user under the Domain drop-down | ||
+ | - Locate your user. | ||
+ | - **Note**__Underlined Text__: At this time, only users can use these permissions. For more information, see Unable to administer vCenter Single Sign-On after adding a User Group and individual users from a Directory Service (OpenLDAP or Active Directory) (2095342). | ||
+ | - Click **Add** | ||
+ | - Click **OK** | ||
+ | Once completed, log out of the vSphere Web Client and log in with your user account. Confirm you are able to access the **System Configuration** section. | ||
- | Once completed, log out of the vSphere Web Client and log in with your user account. Confirm you are able to access the Users and Groups and Configuration sections under Single Sign-On. | + | * To access the Licensing Section |
- | To access the System Configuration Section | + | |
- | Before you begin, ensure your user account has Single Sign-On Administration permissions. | + | Users can utilize the ''Administrator'' default role under **Global Permissions** to access the **Licensing** sections. This section details out how to create a custom role to only provide users with the Licensing sections. |
- | Log in to the vSphere Web Client with your user account or with the Administrator@vsphere.local | + | |
- | Navigate to Administration > Single Sign-On > Users and Groups | + | |
- | Under vCenter Users and Groups, select the Groups tab | + | |
- | Locate the SystemConfiguration.Administrators Group | + | |
- | Under Group Members, click the Add member () icon | + | |
- | In the Add Principals window, select the appropriate domain for your user under the Domain drop-down | + | |
- | Locate your user. | + | |
- | Note: At this time, only users can use these permissions. For more information, see Unable to administer vCenter Single Sign-On after adding a User Group and individual users from a Directory Service (OpenLDAP or Active Directory) (2095342). | + | - Log in to the vSphere Web Client with the ''Administrator@vsphere.local'' |
- | + | - Create a **Licensing Administration Role**: | |
- | Click Add | + | * Navigate to **Administration** > **Access Control** > **Roles** |
- | Click OK | + | * Click **Create new role** () icon |
- | Once completed, log out of the vSphere Web Client and log in with your user account. Confirm you are able to access the System Configuration section. | + | * In the **Create Role** window, **add** a **Role Name**. |
- | To access the Licensing Section | + | * **__Note__**: For this article, we use **Licensing Administration** |
- | + | * Under the Privileges section, locate Global. | |
- | Users can utilize the Administrator default role under Global Permissions to access the Licensing sections. This section details out how to create a custom role to only provide users with the Licensing sections. | + | * Expand Global and select Licenses. This will add a checkbox next to the Privileged. |
- | Log in to the vSphere Web Client with the Administrator@vsphere.local | + | * Click OK to save and close the new role |
- | Create a Licensing Administration Role: | + | - Adding the Licensing Administration Role |
- | Navigate to Administration > Access Control > Roles | + | - Navigate to Administration > Access Control > Global Permissions |
- | Click Create new role () icon | + | - Click Add permission () icon |
- | In the Create Role window, add a Role Name. | + | - In the Global Permissions Root - Add Permissions window, under Assigned Role, select Licensing Administration from the drop-down |
- | + | - Under the Users and Groups section, click Add | |
- | Note: For this article, we use Licensing Administration | + | - In the Select Users/Groups window, select the appropriate domain for your user under the Domain drop-down |
- | + | - Locate your user or group | |
- | Under the Privileges section, locate Global. | + | - Click Add |
- | Expand Global and select Licenses. This will add a checkbox next to the Privileged. | + | - Click OK |
- | Click OK to save and close the new role | + | |
- | Adding the Licensing Administration Role | + | |
- | Navigate to Administration > Access Control > Global Permissions | + | |
- | Click Add permission () icon | + | |
- | In the Global Permissions Root - Add Permissions window, under Assigned Role, select Licensing Administration from the drop-down | + | |
- | Under the Users and Groups section, click Add | + | |
- | In the Select Users/Groups window, select the appropriate domain for your user under the Domain drop-down | + | |
- | Locate your user or group | + | |
- | Click Add | + | |
- | Click OK | + | |
Once completed, log out of the vSphere Web Client and log in with your user account assigned the new role. Confirm you are able to access the Licenses and Reports sections under Licensing. | Once completed, log out of the vSphere Web Client and log in with your user account assigned the new role. Confirm you are able to access the Licenses and Reports sections under Licensing. |