6.0.3

Table Of Contents
Hierarchical Inheritance of Permissions
When you assign a permission to an object, you can choose whether the permission propagates down the
object hierarchy. You set propagation for each permission. Propagation is not universally applied.
Permissions dened for a child object always override the permissions that are propagated from parent
objects.
The gure illustrates the inventory hierarchy and the paths by which permissions can propagate.
N Global permissions support assigning privileges across solutions from a global root object. See
“Global Permissions,” on page 144.
Figure 42. vSphere Inventory Hierarchy
template
host
VDS datastore
cluster
vApp
vApp
vApp
virtual
machine
virtual
machine
resource
pool
resource
pool
virtual
machine
virtual
machine
resource
pool
standard
switch
datastore
cluster
distributed
port group
VM folder host folder
data center
vCenter Server
(vCenter Server instance level)
network
folder
datastore
folder
data center
folder
root object
(global permissions level)
tag category
tag
content library
library item
vSphere Security
138 VMware, Inc.