Events
Apr 29, 2 PM - Apr 30, 7 PM
Join the ultimate Windows Server virtual event April 29-30 for deep-dive technical sessions and live Q&A with Microsoft engineers.
Sign up nowThis browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
System Center Virtual Machine Manager (VMM) allows you to manage roles and permissions. VMM provides:
The following table summarizes VMM user roles.
VMM user role | Permissions | Details |
---|---|---|
Administrator role | Members of this role can perform all administrative actions on all objects that VMM manages. | Only administrators can add a WSUS server to VMM to enable updates of the VMM fabric through VMM. |
Virtual machine administrator | Administrators can create the role (applicable for VMM 2019 and later). | Delegated administrator can create VM administrator role that includes entire scope or a subset of their scope, library servers, and Run-As accounts. |
Fabric administrator (delegated administrator) | Members of this role can perform all administrative tasks within their assigned host groups, clouds, and library servers. | Delegated administrators can't modify VMM settings, add or remove members of the administrators user role, or add WSUS servers. |
Read-Only administrator | Members of this role can view properties, status, and job status of objects within their assigned host groups, clouds, and library servers, but they can't modify the objects. | The read-only administrator can also view Run As accounts that administrators or delegated administrators have specified for that read-only administrator user role. |
Tenant administrator | Members of this role can manage self-service users and VM networks. | Tenant administrators can create, deploy, and manage their own virtual machines and services by using the VMM console or a web portal. Tenant administrators can also specify which tasks the self-service users can perform on their virtual machines and services. Tenant administrators can place quotas on computing resources and virtual machines. |
Tenant administrator | Members of this role can manage self-service users and VM networks. | Tenant administrators can create, deploy, and manage their own virtual machines and services using the VMM console or a web portal. Tenant administrators can also specify which tasks the self-service users can perform on their virtual machines and services. Tenant administrators can place quotas on computing resources and virtual machines. |
Application administrator (Self-Service User) | Members of this role can create, deploy, and manage their own virtual machines and services. | They can manage VMM using the VMM console. |
VMM user role | Permissions | Details |
---|---|---|
Administrator role | Members of this role can perform all administrative actions on all objects that VMM manages. | Only administrators can add a WSUS server to VMM to enable updates of the VMM fabric through VMM. |
Virtual machine administrator | Administrators can create the role. | Delegated administrator can create VM administrator role that includes entire scope or a subset of their scope, library servers, and Run-As accounts. |
Fabric administrator (delegated administrator) | Members of this role can perform all administrative tasks within their assigned host groups, clouds, and library servers. | Delegated administrators can't modify VMM settings, add or remove members of the administrators user role, or add WSUS servers. |
Read-Only administrator | Members of this role can view properties, status, and job status of objects within their assigned host groups, clouds, and library servers, but they can't modify the objects. | The read-only administrator can also view Run As accounts that administrators or delegated administrators have specified for that read-only administrator user role. |
Tenant administrator | Members of this role can manage self-service users and VM networks. | Tenant administrators can create, deploy, and manage their own virtual machines and services using the VMM console or a web portal. Tenant administrators can also specify which tasks the self-service users can perform on their virtual machines and services. Tenant administrators can place quotas on computing resources and virtual machines. |
Application administrator (Self-Service User) | Members of this role can create, deploy, and manage their own virtual machines and services. | They can manage VMM using the VMM console. |
There are different types of Run As accounts:
Note
Events
Apr 29, 2 PM - Apr 30, 7 PM
Join the ultimate Windows Server virtual event April 29-30 for deep-dive technical sessions and live Q&A with Microsoft engineers.
Sign up nowTraining
Module
Manage roles and role groups in Microsoft 365 - Training
This module examines the use of roles and role groups in the Microsoft 365 permission model, including role management, best practices when configuring admin roles, delegating roles, and elevating privileges.
Certification
Microsoft Certified: Identity and Access Administrator Associate - Certifications
Demonstrate the features of Microsoft Entra ID to modernize identity solutions, implement hybrid solutions, and implement identity governance.