Configuring Object Level Roles in VCF Operations
Next, let’s look at adding roles at an object level.
We can use the groups imported from the VCF SSO that we just configured, or we can directly add users from our Active Directory.
If you want to add Active Directory as a source for users and groups, go to Operate > Control Panel > Authentication Sources > press Add > select Active Directory from the drop-down menu, and populate the required fields.

From here, you can navigate to Operate > Control Panel > Access Control > Groups > press Import from Sources > select your recently added AD, search for your users, and press Finish.

We will now want to identify the object-level scope for these users:
From the Access Control page, navigate to Scope and press Add. You can select the specific vCenters, clusters, adapters, etc. that you want your users to have access to in VCF Operations:

Press Save, then navigate back to Groups and select Edit on your recently added group. From here, you can set the scope and roles:

Press Save.
Congratulations! You’ve just created object-level roles inside VCF Operations.



Comments