Installation guide
Table 7-3. Network Privileges
Privilege Name Actions Granted to Users Affects
Pair with
Object
Effective on
Object
Assign Network Assign a network to a virtual
machine.
VCenter Servers virtual
machine
network, virtual
machine
Configure
Network
Configure a network. hosts, vCenter Servers network,
network
folder
networks, virtual
machines
Delete Network Remove a network. hosts, vCenter Servers datacenter datacenters
Move Network Move a network between folders in
the inventory.
NOTE Privileges are required on both
the source and destination objects.
hosts, vCenter Servers network,
source and
destination
networks
Update Datastore Permissions
You must change Read-only nonpropagating datastore permissions to propagating datastore permissions in
order for users to access the datastores. You can assign datastore permissions on datastores or folders
containing datastores.
Prerequisites
Before performing the upgrade procedure, determine which users need access to each datastore and which
privileges each user needs. If necessary, define new datastore roles or modify the Database Consumer sample
role. This sample role assigns the Allocate Space privilege to the datastore, which enables users to perform
basic virtual machine operations, such as creating clones and taking snapshots. In addition, organize your
datastores in folders that coincide with users' access needs.
NOTE The Read-only propagating permission on a datacenter, in addition to all permissions you have set,
will be kept intact after the datastore permissions upgrade.
Procedure
1 Log in to vSphere Client as an administrator.
2 On the Home page, click Datastores to display the datastores in the inventory.
3 Select the datastore or datastore folder and click the Permissions tab.
4 Right-click in the Permissions tab and from the context pop-up menu, choose Add Permission.
5 In the Assigned Role pane, assign a role.
n
To assign specific datastore privileges defined in a role by your company, choose the custom role.
n
To migrate read-only nonpropagating datacenter permissions to propagating datastore permissions,
choose Datastore Consumer (sample). This role assigns the Allocate Space privilege to users, which
is required so that users can consume space on the datastores on which this role is granted. In order
to perform a space-consuming operation, such as creating a virtual disk or taking a snapshot, the user
must also have the appropriate virtual machine privileges granted for these operations.
n
To assign Read-only datastore privileges, choose Read-only.
This role enables users to browse the datastore without giving them other datastore privileges. For
example, choose Read-only for users who need to attach CD/DVD-ROM ISO images to a datastore.
6 Select Propagate to Child Objects.
7 In the Users and Groups pane, click Add.
Chapter 7 Upgrading Datastore and Network Permissions
VMware, Inc. 51