User Roles
Cisco UCS Director supports the following user roles:
-
All Policy Admin
-
Billing Admin
-
Computing Admin
-
Group Admin—An end user with the privilege of adding users. This user can use the End User Portal.
-
IS Admin
-
MSP Admin
-
Network Admin
-
Operator
-
Service End User—This user can only view and use the End User Portal.
-
Storage Admin
-
System Admin
These user roles are system-defined and available in Cisco UCS Director by default. You can determine if a role is available in the system by default, if the Default Role column in the Users page is marked with Yes.
Note |
As an administrator in Cisco UCS Director, you can assign users to system-provided user roles or to custom-defined user roles. In addition, at a later point in time, you can view information on the role that a user is assigned to. For more information, see Viewing User Role Information. |
As an administrator in the system, you can perform the following tasks with user roles:
-
Create a custom user role in the system, and create user accounts with this role or assign the role to existing users.
When you create a new user role, you can specify if the role is that of an administrator or an end user. For more information on creating a user role, see Adding a User Role. For information on creating user accounts for a role, see Adding Users.
-
Modify existing user roles, including default roles, to change menu settings and read/write permissions for users associated with that role.
The procedure to modify menu settings and permissions for a role is the same as the procedure to add a user role.
Defining Permissions to Perform VM Management Tasks to Users
Previously, user permissions for VM management tasks could only be created by defining them in an end-user self-service policy. As an administrator in the system, you can now map permissions to perform VM management tasks to any user role. Users that are mapped to the given role can complete the selected VM management related tasks. However, to assign VM management tasks to end users using the end-user self service policy, you must first disable all VM management actions for this user role, and then enable all other management tasks.
For any user in the system, the capability to perform VM management tasks is determined by the following:
-
The permissions assigned to the user role that the user is mapped to
-
The end user self-service policy that is mapped to the VDC.
If you have upgraded to the current release, then the permissions to perform VM management tasks is retained in the end user self service policy that was created with the previous release version. However, the permissions that you defined or set for the user role after upgrading to the current release, takes precedence.
Note |
You can provide permissions to perform VM management tasks to other administrators, such as MSP Admin or Group Admin, by defining them in the user role only. |