Assign roles to users and groups 编辑
All Citrix Hypervisor users must have an RBAC role. In Citrix Hypervisor, you must first assign a role to the newly created user before they can use the account. Citrix Hypervisor does not automatically assign a role to the newly created user. As a result, these accounts do not have any access to the Citrix Hypervisor pool until you assign them a role.
Note:
Before you can assign a role to a user or group, you must add the user or group’s Active Directory account to the Citrix Hypervisor pool. Add the AD account after joining the associated domain. For more information, see Join a domain and add RBAC users.
You can assign a user a different role by one of the following methods:
- Change the role assigned to the user in the Select Roles dialog in Citrix Hypervisor Center. This action requires the Assign/modify role permission, which is only available to a Pool Administrator.
- Modify the user’s group membership in your Active Directory to make the user part of a group that is assigned a different role.
If an administrator indirectly applies multiple roles to a user, Citrix Hypervisor grants the user the permissions from the highest role that the user is assigned to.
To change or assign a role to a user or group
- In the Resources pane, select the pool or server that contains the user or group.
- Select the Users tab.
- In the Users and Groups with Access pane, select the user or group to which you want to assign permissions.
- Select Change Role.
In the Select Roles dialog, select the role you want to apply and click Save. For information about the permissions associated with each role, see Definitions of RBAC roles and permissions.
Tip:
When you are assigning a role, you can select multiple users simultaneously by pressing the CTRL key and selecting the user accounts.
(Optional) When changing a role, if the user is logged on to the pool and you want them to receive their new permissions immediately, click Logout User. This action disconnects the user’s sessions on the pool so the user receives a new session with the modified role.
Note:
When changing a role, the user must log out and log back in again for the new role to take effect. Force this log out by clicking the Logout User button. To force a logout, the user requires the Logout active user connections permission. This permission is available to a Pool Administrator or Pool Operator.
Note:
If you remove the Pool Admin role from a user, consider also changing the server root password and rotating the pool secret. For more information, see Pool Security.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论