6.0.3

Table Of Contents
Most inventory objects inherit permissions from a single parent object in the hierarchy. For example, a
datastore inherits permissions from either its parent datastore folder or parent data center. Virtual machines
inherit permissions from both the parent virtual machine folder and the parent host, cluster, or resource
pool simultaneously.
For example, you can set permissions for a distributed switch and its associated distributed port groups, by
seing permissions on a parent object, such as a folder or data center. You must also select the option to
propagate these permissions to child objects.
Permissions take several forms in the hierarchy:
Managed entities
Privileged users can dene permissions on managed entities.
n
Clusters
n
Data centers
n
Datastores
n
Datastore clusters
n
Folders
n
Hosts
n
Networks (except vSphere Distributed Switches)
n
Distributed port groups
n
Resource pools
n
Templates
n
Virtual machines
n
vSphere vApps
Global entities
You cannot modify permissions on entities that derive permissions from the
root vCenter Server system.
n
Custom elds
n
Licenses
n
Roles
n
Statistics intervals
n
Sessions
Multiple Permission Settings
Objects might have multiple permissions, but only one permission for each user or group. For example, one
permission might specify that Group B has Administrator privileges on the object, and another permission
might specify that Group B might have Virtual Machine Administrator privileges on the same object.
If an object inherits permissions from two parent objects, the permissions on one object are added to the
permissions on the other object. For example, if a virtual machine is in a virtual machine folder and also
belongs to a resource pool, that virtual machine inherits all permission seings from both the virtual
machine folder and the resource pool.
Permissions applied on a child object always override permissions that are applied on a parent object. See
“Example 2: Child Permissions Overriding Parent Permissions,” on page 140.
Chapter 4 vSphere Permissions and User Management Tasks
VMware, Inc. 139