6.0.3

Table Of Contents
Create a Custom Role
You can create vCenter Server custom roles to suit the access control needs of your environment.
If you create or edit a role on a vCenter Server system that is part of the same vCenter Single Sign-On
domain as other vCenter Server systems, the VMware Directory Service (vmdir) propagates the changes that
you make to all other vCenter Server systems in the group. Assignments of roles to specic users and objects
are not shared across vCenter Server systems.
Prerequisites
Verify that you are logged in as a user with Administrator privileges.
Procedure
1 Log in to vCenter Server with the vSphere Web Client.
2 Select Home, click Administration, and click Roles.
3 Click the Create role action (+) buon.
4 Type a name for the new role.
5 Select privileges for the role and click OK.
Clone a Role
You can make a copy of an existing role, rename it, and edit it. When you make a copy, the new role is not
applied to any users or groups and objects. You must assign the role to users or groups and objects.
If you create or edit a role on a vCenter Server system that is part of the same vCenter Single Sign-On
domain as other vCenter Server systems, the VMware Directory Service (vmdir) propagates the changes that
you make to all other vCenter Server systems in the group. Assignments of roles to specic users and objects
are not shared across vCenter Server systems.
Prerequisites
Verify that you are logged in as a user with Administrator privileges.
Procedure
1 Log in to vCenter Server with the vSphere Web Client.
2 Select Home, click Administration, and click Roles.
3 Select a role, and click the Clone role action icon.
4 Type a name for the cloned role.
5 Select or deselect privileges for the role and click OK.
Edit a Role
When you edit a role, you can change the privileges selected for that role. When completed, these privileges
are applied to any user or group that is assigned the edited role.
If you create or edit a role on a vCenter Server system that is part of the same vCenter Single Sign-On
domain as other vCenter Server systems, the VMware Directory Service (vmdir) propagates the changes that
you make to all other vCenter Server systems in the group. Assignments of roles to specic users and objects
are not shared across vCenter Server systems.
Prerequisites
Verify that you are logged in as a user with Administrator privileges.
Chapter 4 vSphere Permissions and User Management Tasks
VMware, Inc. 149