I created a new vRealize Operations 6.6.1 instance and added a vCenter. I logged in to the vCenter and saw new Role privileges available under Global including "vrealize operations read only role". In vrealize operations, I provided Read only permissions to an AD group but did NOT apply any permissions for them directly in the vcenter itself so they currently can access vRealize for troubleshooting, etc. but cannot access the vCenter via vSphere or Web Client. This is what I hoped to achieve but now I want to determine what the benefit would be for assigning the new vrealize operations privileges to AD groups in vCenter since the privileges do not appear to be required.
↧