To set the scope of delegated administration, the administrator runs the Add Delegated Administrator Configuration workflow. For example, a certain delegated administrator might be limited to performing operations on some pools, and a different delegated administrator might be limited to different pools.
Running the Add Delegated Administrator Configuration workflow is required for configuring the vRealize Orchestrator Plug-in for Horizon. At a minimum, the primary administrator must be assigned to the pools. Using this workflow, the administrator has tight control over which pools can have distributed administration and which workflows can be used.
Prerequisites
- Verify that you have administrator credentials for the vRealize Orchestrator server. The account must be a member of the vRealize Orchestrator Admin group configured to authenticate through vCenter Single Sign-On.
- Verify that you have provided access rights for the delegated administrators group to view and run workflows for vRealize Orchestrator Plug-in for Horizon. See Provide Access Rights to the vRealize Orchestrator Plug-in for Horizon Workflows.
- Verify that a connection has been made to the pod by running the Add View Pod in Configuration workflow. See Configure the Connection to a Pod in VMware Horizon 8.
Procedure
- Log in to vRealize Orchestrator as an administrator.
- Click the Workflows view in vRealize Orchestrator.
- In the workflows hierarchical list, select Add Delegated Administrator Configuration workflow. and navigate to the
- Right-click the workflow and select Start workflow.
- Use the following information to enter values in the form that appears.
Option Action Horizon View Pod Select an item from the drop-down menu. Items get added to this list through the Add View Pod in Configuration workflow. Select Desktop Pool IDs Click Not Set and add one or more pools from the New value drop-down menu. Select Application Pool IDs Click Not Set and add one or more pools from the New value drop-down menu. Add Delegated Administrator user or group? Select an item from the drop-down menu. You can add users one by one or add a group from Active Directory. Note: To add a group, you must be using vRealize Orchestrator 6.0.4 or a later release.Delegated Administrator User/Group Name Click Not Set and, in the Filter text box, enter the name of the user or group you included in the delegated administrators group. Note: If you add a user name for a delegated administrator and the user name contains any special characters, the workflow will report success, but the delegated administrator configuration will not be added for that user.Select Global Entitlement (Displayed only if global entitlements have been created and initiated for a pod federation in a Cloud Pod Architecture environment) Click Not Set and add an item from the New value drop-down menu. - To run the workflow, click Submit.
Results
The delegated administrator user or group that you selected can now manage the desktop and application pools that you specified in the form.