6.0

Table Of Contents
4 Select Properties.
5 Select a role for the user or group from the drop-down menu.
6 To propagate the privileges to the children of the assigned inventory object, click the Propagate check
box and click OK.
Remove Permissions
Removing a permission for a user does not remove the user from the list of those available. It also does not
remove the role from the list of available items. It removes the user and role pair from the selected inventory
object.
Prerequisites
n
Open a vSphere Client session to an ESXi host.
Procedure
1 From the vSphere Client, click the Inventory button.
2 Expand the inventory as needed and click the appropriate object.
3 Click the Permissions tab.
4 Click the appropriate line item to select the user and role pair.
5 Select Inventory > Permissions > Delete.
Change Permission Validation Settings
vCenter Server periodically validates its user and group lists against the users and groups in the Windows
Active Directory domain. It then removes users or groups that no longer exist in the domain. You can
change the interval between validations.
Procedure
1 From the vSphere Client connected to a vCenter Server system, select Administration > vCenter Server
Settings.
2 In the navigation pane, select Active Directory.
3 (Optional) Deselect the Enable Validation check box to disable validation.
Validation is enabled by default. Users and groups are validated when vCenter Server system starts,
even if validation is disabled.
4 If validation is enabled, enter a value in the Validation Period text box to specify a time, in minutes,
between validations.
Managing ESXi Roles
ESXi grants access to objects only to users who are assigned permissions for the object. When you assign a
user permissions for the object, you do so by pairing the user with a role. A role is a predefined set of
privileges.
ESXi hosts provide three default roles, and you cannot change the privileges associated with these roles.
Each subsequent default role includes the privileges of the previous role. For example, the Administrator
role inherits the privileges of the Read Only role. Roles you create yourself do not inherit privileges from
any of the default roles.
Chapter 7 ESXi Authentication and User Management
VMware, Inc. 73