Installation guide

Table Of Contents
Figure 18-2. vSphere Inventory Hierarchy
template host network datastore
virtual machine resource pool cluster
host
virtual machine
VM folder host folder network folder datastore folder
data center folder
data center
root folder
Most inventory objects inherit permissions from a single parent object in the hierarchy. For example, a datastore
inherits permissions from either its parent datastore folder or parent datacenter. However, virtual machines
inherit permissions from both the parent virtual machine folder and the parent host, cluster, or resource pool
simultaneously. This means that to restrict a user’s privileges on a virtual machine, you must set permissions
on both the parent folder and the parent host, cluster or resource pool for that virtual machine.
You cannot set permissions directly on a vNetwork Distributed Switches. To set permissions for a vNetwork
Distributed Switch and its associated dvPort Groups, set permissions on a parent object, such a folder or
datacenter, and select the option to propagate these permissions to child objects.
Permissions take several forms in the hierarchy:
Managed entities
Can have permissions defined on them.
n
Clusters
n
Datacenters
n
Datastores
n
Folders
Chapter 18 Managing Users, Groups, Roles, and Permissions
VMware, Inc. 221