HCX configuration and operation requires an understanding of the various accounts and roles involved in deploying, managing, and operating the system.
User Accounts
HCX has the following account requirements:
Account |
Requirements |
Additional Information |
---|---|---|
admin |
|
|
Account for vCenter Server Registration |
The account must belong to the vSphere administrators group, or have the administrator role assigned. |
|
Account for NSX Registration |
If NSX-T, this account must have the Enterprise Admin role assigned. If NSXv, this account must have the Enterprise Administrator role assigned. |
Note: This account is generally not required for HCX Connector installations. It is required only when extending NSX Segments, or migrating NSX Tags.
|
Account for vCloud Director Registration |
The account must have the System Administrator role assigned. |
Note: This account is only required for provider installations of VMware HCX with vCloud Director. A tenant does not require this account.
|
Accounts for HCX Role Mapping (This refers to SSO User accounts that will be mapped to an HCX role.) |
The user’s group must be included in the HCX Role Mapping configuration. |
|
Site Pairing Accounts |
The user’s group must be included in the HCX Role Mapping configuration (on the remote HCX Cloud system being paired). The user's group can be in either the HCX Administrators group or the HCX Tenant group. | The site pairing user is entered along with the HCX Cloud’s URL in the site pairing configuration on the source HCX Manager system. The following are typical scenarios:
|
HCX Role Mapping
Access to HCX services and features depends on the assigned user role. User roles are assigned in the HCX appliance management interface during the initial HCX activation and configuration.
- HCX Administrator
-
SSO groups assigned to the HCX Administrator role have unrestricted access to perform all HCX configurations and operations.
- HCX Tenant
-
This role is intended for use by HCX Service Providers. SSO groups assigned to the HCX Tenant role cannot add or delete HCX Network Profiles.
Note:The HCX Tenant role is not available in HCX Connector deployments.
vSphere Privileges for Migration Operations
User groups assigned to the HCX Administrator or the HCX Tenant role must have these vSphere vCenter Server privileges to perform migrations.
vCenter Resource Type |
User Privilege |
Description |
---|---|---|
ComputeResource |
|
Privileges required on the destination ComputeResource object when performing a migration operation. |
HostSystem |
|
Privileges required on the destination HostSystem object when performing a migration operation. |
ClusterComputeResource |
|
Privileges required on the destination ClusterComputeResource object when performing a migration operation. |
ResourcePool |
|
Privileges required on the destination ResourcePool object when performing a migration operation. |
Folder |
|
Privileges required on the destination Folder object when performing a migration operation. |
Datacenter |
|
Privileges required on the destination Datacenter objects when performing a migration operation. |
Datastore |
|
Privileges required on the destination Datastore objects when performing a migration operation. |
DistributedVirtualPortgroup/Network |
Network.Assign |
Privileges required on the destination Network objects when performing a migration operation. |
VirtualMachine |
|
Privileges required on the source Virtual Machines when performing a migration operation. |