6.0.1

Table Of Contents
Required Privileges for Common
Tasks 13
Many tasks require permissions on more than one object in the inventory. You can review the privileges that
are required to perform the tasks and, where applicable, the appropriate sample roles.
The table below lists common tasks that require more than one privilege. You can add permissions to
inventory objects by pairing a user with one of the predefined roles, or you can create custom roles with the
set of privileges that you expect to use multiple times.
If the task that you want to perform is not in this table, the following rules can help you determine where
you must assign permissions to allow particular operations:
n
Any operation that consumes storage space, such as creating a virtual disk or taking a snapshot,
requires the Datastore.Allocate Space privilege on the target datastore, as well as the privilege to
perform the operation itself.
n
Moving an object in the inventory hierarchy requires appropriate privileges on the object itself, the
source parent object (such as a folder or cluster), and the destination parent object.
n
Each host and cluster has its own implicit resource pool that contains all the resources of that host or
cluster. Deploying a virtual machine directly to a host or cluster requires the Resource.Assign Virtual
Machine to Resource Pool privilege.
Table 131. Required Privileges for Common Tasks
Task Required Privileges Applicable Role
Create a virtual machine On the destination folder or data center:
n
Virtual machine.Inventory.Create new
n
Virtual machine.Configuration.Add new disk (if creating a new
virtual disk)
n
Virtual machine.Configuration.Add existing disk (if using an
existing virtual disk)
n
Virtual machine.Configuration.Raw device (if using an RDM or
SCSI pass-through device)
Administrator
On the destination host, cluster, or resource pool:
Resource.Assign virtual machine to resource pool
Resource pool
administrator or
Administrator
On the destination datastore or folder containing a datastore:
Datastore.Allocate space
Datastore
Consumer or
Administrator
On the network that the virtual machine will be assigned to:
Network.Assign network
Network
Consumer or
Administrator
VMware, Inc. 249