---
name: vmwaresolutions-vrw-iam-nsxt
title: NSX administration interface identity and access management
description: As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
last-updated: 2025-10-24
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/vmwaresolutions?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# NSX administration interface identity and access management
{: #vrw-iam-nsxt}

As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
{: deprecated}

**End of Marketing**: As of 31 October 2025, new deployments of VMware Solutions offerings are no longer available for new customers. Existing customers can still use and expand their active VMware® workloads on IBM Cloud&reg;. For more information, see [End of Marketing for VMware on IBM Cloud](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-eos-vms&format=markdown).
{: note}

The following main principles or requirements apply:
* `Infrastructure Admin` has `execute` and `full access` to all components.
* `Auditor` has read-only access to all components.

## NSX role mapping
{: #vrw-iam-nsxt-rolemapping}

| VMware NSX® component | Auditor | Infrastructure admin |
| --------------- |-------- |--------------------- |
| Controllers     | Read | Full |
| Transport Nodes | Read | Full |
| Edge Nodes      | Read | Full |
| Segments - VLAN | Read | Full |
| Segments - Overlay | Read | Full |
| T0 - Tenant     | Read | Full |
| T0 - Transit    | Read| Full |
| T0 - Management | Read | Full |
| T1s - Tenant    | Read | Full |
| T1s - Services | Read | Full |
| T1s - Management | Read | Full |
{: caption="NSX role mapping" caption-side="bottom"}

The roles and privileges for load balancing, firewall rules, and VPN services follow the T0/T1 roles and privileges.

## NSX roles
{: #vrw-iam-nsxt-roles}

NSX Data Center has the following built-in roles. You cannot add any new roles.
* Enterprise administrator
* Auditor
* Network engineer
* Network operations
* Security engineer
* Security operations
* Load balancer administrator
* Load balancer auditor
* VPN administrator
* Guest introspection administrator
* Network introspection administrator

## NSX user interface user IDs
{: #vrw-iam-nsxt-ids}

| User     | User ID      | Description |
|:---------|:-------------|:------------|
| Privileged user | `admin` | Used post-deployment to manage NSX VTEP IP addresses and to manage host and cluster configuration when hosts and clusters are added and removed. Also, used to manage ESG configuration for services that require public network access for licensing, activation, or usage reporting. |
| IBM automation | `automation_admin` | Automation account used by IBM. It uses the principle identity functions to create configuration and protect it with a certificate. |
{: caption="NSX user IDs" caption-side="bottom"}

For more information, see the [Role-Based Access Control](https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-2/administration-guide/authentication-and-authorization/role-based-access-control.html){: external}.

## Related links
{: #vrw-iam-nsxt-related}

* [IBM Cloud compliance programs](https://www.ibm.com/products/cloud/compliance){: external}
* [IBM Cloud Hyper Protect Crypto Services API](https://cloud.ibm.com/apidocs/hs-crypto)