So, it used to be easy - just make sure a user was in the local administrators group of the vcenter server, and .... voila!
Now - with SSO - how do we do it? I've been asked how-to, and discovered I "just don't know" ...
I *think* we should still be able to use the local group, but I'd like to understand what the options are, as well.
If we want to give a user rights to view/edit existing VMs, but not create anything new, for example - how do we accomplish this? I don't think going into the vcenter administration menu options really is the way to do it, is it? If there is an individual user or a group in AD that we want to have a specific set of rights, how do we configure that?
(ps - I know this is in the docs, and I'll trudge through and read a 1000 pages to figure it out, if needed - but I'm guessing that someone here has "the skinny" and can describe it quick and dirty, enough so that we can tumble through and figure it out the rest of the way ourselves ...)
TIA!