Unsolved
This post is more than 5 years old
1 Rookie
•
44 Posts
0
2527
October 31st, 2017 06:00
RecoverPoint for VM -- vCenter permission
Hi guys,
What vCenter role(permissions) can operation RP4VM plugin (add CG/delete CG/view CG status/operate CG), but can not touch the VM itself, is there any document explain it ?
Thank you.
No Events found!
Idan
675 Posts
0
November 22nd, 2017 00:00
Hi there,
RPVM requires vCenter admin privileges for deployment and ongoing operations. We're working on documenting a more granular list of roles we need. If you need more info, feel free to contact me offline.
Regards,
Idan Kentor
RecoverPoint Corporate Systems Engineering
@IdanKentor
idan.kentor@emc.com
JonK1
2 Intern
•
247 Posts
0
January 12th, 2018 01:00
Hi Idan,
Is there any update on the granular list of permissions required? Our customer (understandably) doesn't really like handing out full admin rights...
Thanks,
Jon
Idan
675 Posts
0
January 12th, 2018 02:00
Not yet Jon (we’re still working on it) but just to clarify, it’s certainly possible to configure the admin user RPVM would use for specific ESX Clusters/DCs/etc.
mkozak82
7 Posts
0
May 14th, 2018 11:00
It appears there is no way of limiting user access to RP4VM. In testing I've found if the user has any permission to vCenter including Read-Only access, they're able to perform any action including failing over any consistency group. All RP4VM actions are performed by the admin user instead of the logged in user and there are no access permissions to keep them out of the plugin.
Idan
675 Posts
0
May 15th, 2018 03:00
That is not accurate, we have a solution which hides the plugin from users without a certain privilege.
Contact me offline for more info.
Regards,
Idan Kentor
RecoverPoint Corporate Systems Engineering
@IdanKentor
idan.kentor@emc.com
mkozak82
7 Posts
0
May 15th, 2018 07:00
Can you provide the documentation on how to do this? I looked and wasn’t able to find it. Also is there the ability to limit permissions for a user to certain consistency groups?
Michael Kozak | Principal Network & Systems Administrator
mkozak@smg.com | (P) 816.841.5625 | (M) 785.304.3670
Idan
675 Posts
0
May 16th, 2018 06:00
Michael,
I'll provide more details offline, I've seen your email and I'll get to it.