6.0.3

Table Of Contents
Distributed Switch Privileges
Distributed Switch privileges control the ability to perform tasks related to the management of Distributed
Switch instances.
You can set this privilege at dierent levels in the hierarchy. For example, if you set a privilege at the folder
level, you can propagate the privilege to one or more objects within the folder. The object listed in the
Required On column must have the privilege set, either directly or inherited.
Table 108. vSphere Distributed Switch Privileges
Privilege Name Description Required On
Distributed switch.Create Allows creation of a distributed switch. Data centers, Network
folders
Distributed switch.Delete Allows removal of a distributed switch.
To have permission to perform this operation, a user or group must
have this privilege assigned in both the object and its parent object.
Distributed switches
Distributed switch.Host
operation
Allows changing the host members of a distributed switch. Distributed switches
Distributed switch.Modify Allows changing the conguration of a distributed switch. Distributed switches
Distributed switch.Move Allows moving a vSphere Distributed Switch to another folder. Distributed switches
Distributed switch.Network
I/O control operation
Allow changing the resource seings for a vSphere Distributed Switch. Distributed switches
Distributed switch.Policy
operation
Allows changing the policy of a vSphere Distributed Switch. Distributed switches
Distributed switch .Port
 operation
Allow changing the conguration of a port in a vSphere Distributed
Switch.
Distributed switches
Distributed switch.Port
 operation
Allows changing the seing of a port in a vSphere Distributed Switch. Distributed switches
Distributed switch.VSPAN
operation
Allows changing the VSPAN conguration of a vSphere Distributed
Switch.
Distributed switches
ESX Agent Manager Privileges
ESX Agent Manager privileges control operations related to ESX Agent Manager and agent virtual
machines. The ESX Agent Manager is a service that lets you install management virtual machines, which are
tied to a host and not aected by VMware DRS or other services that migrate virtual machines.
You can set this privilege at dierent levels in the hierarchy. For example, if you set a privilege at the folder
level, you can propagate the privilege to one or more objects within the folder. The object listed in the
Required On column must have the privilege set, either directly or inherited.
Table 109. ESX Agent Manager
Privilege Name Description Required On
ESX Agent
Manager.
Allows deployment of an agent virtual machine on a host or cluster. Virtual machines
ESX Agent
Manager.Modify
Allows modications to an agent virtual machine such as powering o
or deleting the virtual machine.
Virtual machines
ESX Agent View.View Allows viewing of an agent virtual machine. Virtual machines
Chapter 10 Defined Privileges
VMware, Inc. 261