6.0

Table Of Contents
You can create custom roles by using the role-editing facilities in the vSphere Client to create privilege sets
that match your user needs. If you use the vSphere Client connected to vCenter Server to manage ESXi
hosts, you have additional roles to choose from in vCenter Server. Also, the roles you create directly on a
host are not accessible within vCenter Server. You can work with these roles only if you log in to the host
directly from the vSphere Client.
NOTE When you add a custom role and do not assign any privileges to it, the role is created as a Read Only
role with three system-defined privileges: System.Anonymous, System.View, and System.Read.
If you manage ESXi hosts through vCenter Server, maintaining custom roles in the host and vCenter Server
can result in confusion and misuse. In this type of configuration, maintain custom roles only in
vCenter Server.
You can create host roles and set permissions through a direct connection to the ESXi host with the vSphere
Client.
Create a Role
VMware recommends that you create roles to suit the access control needs of your environment.
Prerequisites
Verify that you are logged in as a user with Administrator privileges, such as root or vpxuser.
Procedure
1 On the vSphere Client Home page, click Roles.
2 Right-click the Roles tab information panel and click Add.
3 Type a name for the new role.
4 Select privileges for the role and click OK.
Clone a Role
You can make a copy of an existing role, rename it, and later edit it. When you make a copy, the new role is
not applied to any users or groups and objects. You must assign the role to users or groups and objects.
Prerequisites
Verify that you are logged in as a user with Administrator privileges, such as root or vpxuser.
Procedure
1 On the vSphere Client Home page, click Roles.
2 To select the role to duplicate, click the object in the list of Roles.
3 To clone the selected role, select Administration > Role > Clone.
A duplicate of the role is added to the list of roles. The name is Copy of rolename.
Edit a Role
When you edit a role, you can change the privileges selected for that role. When completed, these privileges
are applied to any user or group assigned the edited role.
Prerequisites
Verify that you are logged in as a user with Administrator privileges, such as root or vpxuser.
vSphere Administration with the vSphere Client
74 VMware, Inc.