Events
Apr 29, 2 PM - Apr 30, 7 PM
Join the ultimate Windows Server virtual event April 29-30 for deep-dive technical sessions and live Q&A with Microsoft engineers.
Sign up nowThis browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
This article describes how to set up System Center Virtual Machine Manager (VMM) user roles.
Learn more about user roles.
Ensure you've the right permissions to create the role or to add users to it.
Administrator role: Administrators can add and remove users.
Delegate Administrator role: Administrators can create the role. Delegated administrators can create delegated administrator roles that include a subset of their scope, library servers, and Run As accounts.
Read-only Administrator role: Administrators can create the role. Delegated administrators can create Read-only Administrator roles that include a subset of their scope, library servers, and Run As accounts.
Tenant Administrator role: Administrators and Delegated administrators can create this role.
The Administrator role is created by default when you install VMM. The user who performs the installation and all domain users in the local Administrators group on the server are added to the Administrator role. You can add or remove members in the role properties.
Select Settings > Create > Create User Role.
In the Create User Role Wizard, enter a name and optional description for the role, and select Next.
In Profile page, select the role, and select Next.
In Members, select Add to add user accounts and Active Directory groups to the user role. Add the members in Select Users, Computers, or Groups, and select Next.
In Scope, select the private clouds or host groups that the members of the role can use. Select Next.
If one or more Quotas pages appear (based on whether you selected private clouds on the previous wizard page), review and specify quotas as needed for each private cloud. Otherwise, skip to the next step. Read-only Administrators can only view items in this defined scope.
To set quotas for the combined use of all members of this user role, use the upper list. To set quotas for each individual member of this user role, use the lower list. By default, quotas are unlimited. To create a limit, clear the appropriate checkbox under Use Maximum and then, under Assigned Quota, select a limit. When you've completed all settings, select Next.
If the Library servers page appears, add one or more library servers.
In Networking, select Add to add the VM networks that the members of this role can use. Select Next.
In Resources, select Add to add resources. In Specify user role data path, select Browse to specify a library path that members of this user role can use to upload data. Select Next.
In Permissions page, select global actions, and any cloud-specific actions that you want to allow members of this role to perform. Select Next.
If the Run As accounts page appears, add Run As accounts that you want the members of this role to be able to use. Otherwise, skip to the next step.
If the Quotas for VM networks page appears, review and specify quotas to limit the number of VM networks that members of this user role can create. Otherwise, skip to the next step.
To limit the combined number of VM networks that can be created by all members of this user role, use the upper setting. To limit the number of VM networks that can be created by each individual member of this user role, use the lower setting.
In Summary page, review the settings, and select Finish to create the role. Verify the role appears in Settings > Security > User Roles.
Events
Apr 29, 2 PM - Apr 30, 7 PM
Join the ultimate Windows Server virtual event April 29-30 for deep-dive technical sessions and live Q&A with Microsoft engineers.
Sign up nowTraining
Module
Configure and manage Hyper-V virtual machines - Training
Configure and manage Hyper-V virtual machines
Certification
Microsoft Certified: Azure Virtual Desktop Specialty - Certifications
Plan, deliver, manage, and monitor virtual desktop experiences and remote apps on Microsoft Azure for any device.
Documentation
Manage roles and permissions in VMM
This article describes how to manage roles and permissions in VMM
Work with VMM as a self-service user
This article describes how to work with VMM as a self-service user
Set up and manage self-service access to SCVMM resources - Azure Arc
This article describes how to use built-in roles to manage granular access to SCVMM resources through Azure Role-based Access Control (RBAC).