RBAC and identity management on vCenter and CSP
VMware Cloud on AWS service access has two authentication domains: the CSP authentication domain and the vCenter authentication domain. With the new version 1.22 release, it is possible to configure federated SSO between CSP and vCenter: when this feature is enabled, a user authenticated through CSP will get access to vCenter Server without additional authentication. Before a user will be able to log in, an appropriate vCenter role must be assigned using the cloudadmin
account.
VMware Cloud on AWS uses a restricted operation model to manage access to vCenter Server. The default administrator user – cloudadmin@vmc.local
– does not have full administrator rights compared to the administrator@vsphere.local
account. This is expected for a managed service and prevents users from accidentally changing the settings having an impact on SLA or environment stability. The permission set available to the cloudadmin
account and the...