Users with new custom organization administrator role cannot manage other user objects.
search cancel

Users with new custom organization administrator role cannot manage other user objects.

book

Article ID: 407572

calendar_today

Updated On:

Products

VMware Cloud Director

Issue/Introduction

  • Custom role is a clone of the default organization administrator role with limited rights.
  • New VMs/objects created by users with the custom role can manage the objects successfully in the organization VDC(OVDC).
  • Any existing VMs owned by other users can only be viewed but not manageable(power operations, consoles etc. are greyed out).

Environment

VMware Cloud Director 10.6.x

Cause

The custom role was missing "Administrator control" rights but had "Administrator view" right.

"Administrator view" right allow users to see any managed object for other users."Administrator control" right allows users to manage any objects owned by other users inside an OVDC. 

Resolution

To resolve the issue, the "Administrator control" right can be added to the custom role. Follow steps in Edit a Custom Tenant Role

Once the right is added, verify the objects owned by other users can be managed successfully(open VM console, power operations etc.)

Additional Information

To compare rights in the custom role to a default role available, refer Rights Included in the Global Tenant Roles in VMware Cloud Director