To activate cloud accounts for vCenter Server and SDDC Manager across VMware Cloud Foundation instances, you add and configure service accounts associated with the solution.
Service Accounts for Intelligent Operations Management
You add and configure accounts associated with vSphere and NSX for activating the VMware Aria Operations cloud accounts.
Design Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
IOM-VAOPS-SEC-005 |
Create and assign least privilege access to an Active Directory user account as a service account in each SDDC Manager instance for application-to-application communication between VMware Aria Operations and SDDC Manager. |
Provides integration and data collection of objects managed by SDDC Manager for a VMware Cloud Foundation instance. |
You must maintain the life cycle, availability, and security controls for the account in Active Directory. |
IOM-VAOPS-SEC-006 |
Define a custom vCenter Server role for VMware Aria Operations that has minimum privileges required to support a vCenter Server cloud account. |
VMware Aria Operations integrates with each workload domain vCenter Server instances using a minimum set of privileges required to support the cloud account. |
|
IOM-VAOPS-SEC-007 |
Create and assign the custom vCenter Server role to an Active Directory user account as a service account for each workload domain vCenter Server instance for application-to-application communication between VMware Aria Operations and vCenter Server. |
|
You must maintain the life cycle, availability, and security controls for the account in Active Directory. |
IOM-VAOPS-SEC-008 |
Use the vCenter Server service account for data collection on vSAN cloud accounts. |
As a service managed by vCenter Server, vSAN does not require separate credentials for the integration to function. |
None. |
IOM-VAOPS-SEC-009 |
Create and assign the Enterprise Admin role using an NSX Principal Identity for each workload domain NSX Local Manager instance for application-to-application communication between VMware Aria Operations and NSX Manager. |
|
You must manage the credential and the life cycle management of certificates and their corresponding private keys. |