You can assign a user account to one or more user groups, assign roles to the account, and associate the account with objects in the vRealize Operations Manager environment that the user is allowed to access. Assign the Administrators role only to specific users who must access objects and perform actions in the entire environment.

To assign groups, roles, and objects to a user account, select Administration and click Access Control. On the User Accounts toolbar, click the plus sign to add an account. To edit a user account, select an existing account, click the pencil icon, and assign groups, roles, and objects to the account in the Add or Edit User workspace.

Access Control Add or Edit User Workspace - Assign Groups, Roles, and Objects Page

Assign Groups Roles, and Objects Options



Select or deselect the groups associated with the user account. To select or deselect all accounts, click the Group Name check box. You cannot add user accounts to groups that you imported from an LDAP database.


Select or deselect the roles associated with the user account so that the user can perform actions and make changes . To select or deselect all roles, click the Role Name check box.


Select the objects that the user can access.

Object View. Displays the selected object type. To select another object type, click the down arrow. For example, expand a vCenter Server instance and select one or more objects, such as data centers and clusters.

Allow access to all objects in the system. To allow the user account to access all objects in the vCenter Server inventory of the vRealize Operations Manager instance, click this check box. For example, click the check box to allow a user, such as an administrator, to access all objects.