March 2018
Beginner
584 pages
14h 51m
English
To access NSX, a user must be assigned to a vCenter role and an NSX role. Without rights to vCenter, the user cannot administer NSX as the NSX plugin access is via the vCenter vSphere web client. The minimum role required in the vCenter is a Read-only role; this way, the user can be restricted to just administer NSX and not vSphere and vice versa.
Users can be assigned to roles directly or via groups. The users can originate from the Single Sign-On (SSO) domain (for example, the vsphere.local domain), an NSX Manager CLI user account, or an external domain registered in SSO or PSC. VMware SSO supports the following identity services based on SAML tokens:
Read now
Unlock full access