Specifications

VMware, Inc. 263
Chapter 17 Managing Users, Groups, Permissions, and Roles
Hierarchical Inheritance
Propagationissetperpermissionrule,notuniversallyapplied.Permissionsdefinedfor
asubobjectalwaysoverridethosepropagatedfromparentobjects.
Withrespecttopermissions,therearethreetypesofelementsinthehierarchy.Theyare:
ManagedentityThesecanhavepermissionsdefinedonthem.
Virtualmachines
Folders
Datacenters
Clusters
Hosts
Resourcepools
Templates
RelatedtoamanagedentityThesecannothavepermissionsdefinedonthem,
butinheritaccessfromtheobjecttheyarerelatedto.Examplesinclude:
Networks
Datastores
GlobalentityThesealwaysgettheirpermissionsfromtherootnode.Examples
include:
Customfields
Licenses
Statisticsintervals
Roles
Sessions
Multiple Permission Settings
Objectsmighthavemultiplepermissions,butatmostoneforeachuserorgroup.
Ifyouapplypermissions,theyoverrideeachotherdownthehierarchy.Ifpermissions
aredefinedonthesameentity,acoupleofsituationsarepossible:
Ifauserisamemberofmultiplegroupswithdifferentpermissions.Foreach
objectthegrouphaspermissionson,thesamepermissionsapplyasifgrantedto
theuserdirectly.
Ifmultiplegrouppermissionsaredefinedonthesameobjectandtheuser
belongstotwoormoreofthosegroups: