Skip to content

Commit 8d34b7f

Browse files
authored
Update concepts-identity.md
Additional notes added to clarify role administration.
1 parent dcfb1b8 commit 8d34b7f

File tree

1 file changed

+7
-3
lines changed

1 file changed

+7
-3
lines changed

articles/azure-vmware/concepts-identity.md

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -53,9 +53,10 @@ The CloudAdmin role in Azure VMware Solution has the following privileges on vCe
5353

5454
### Create custom roles on vCenter Server
5555

56-
Azure VMware Solution supports the use of custom roles with equal or lesser privileges than the CloudAdmin role.
56+
Azure VMware Solution supports the use of custom roles with equal or lesser privileges than the CloudAdmin role. You'll use the CloudAdmin role to create, modify, or delete custom roles with privileges lesser than or equal to their current role.
5757

58-
You'll use the CloudAdmin role to create, modify, or delete custom roles with privileges lesser than or equal to their current role. You can create roles with privileges greater than CloudAdmin. You can't assign the role to any users or groups or delete the role.
58+
>[!NOTE]
59+
>You can create roles with privileges greater than CloudAdmin. However, you can't assign the role to any users or groups or delete the role. Roles that have privileges greater than that of CloudAdmin is unsupported.
5960
6061
To prevent creating roles that can't be assigned or deleted, clone the CloudAdmin role as the basis for creating new custom roles.
6162

@@ -71,7 +72,7 @@ To prevent creating roles that can't be assigned or deleted, clone the CloudAdmi
7172
7273
1. Provide the name you want for the cloned role.
7374

74-
1. Add or remove privileges for the role and select **OK**. The cloned role is visible in the **Roles** list.
75+
1. Remove privileges for the role and select **OK**. The cloned role is visible in the **Roles** list.
7576

7677
#### Apply a custom role
7778

@@ -84,9 +85,12 @@ To prevent creating roles that can't be assigned or deleted, clone the CloudAdmi
8485
1. Search for the user or group after selecting the Identity Source under the **User** section.
8586

8687
1. Select the role that you want to apply to the user or group.
88+
>[!NOTE]
89+
>Attempting to apply a user or group to a role that has privileges greater than that of CloudAdmin will result in errors.
8790
8891
1. Check the **Propagate to children** if needed, and select **OK**. The added permission displays in the **Permissions** section.
8992

93+
9094
## NSX-T Manager access and identity
9195

9296
When a private cloud is provisioned using Azure portal, software-defined data center (SDDC) management components like vCenter Server and NSX-T Manager are provisioned for customers.

0 commit comments

Comments
 (0)