6.0.3

Table Of Contents
Extension Privileges
Extension privileges control the ability to install and manage extensions.
You can set this privilege at dierent levels in the hierarchy. For example, if you set a privilege at the folder
level, you can propagate the privilege to one or more objects within the folder. The object listed in the
Required On column must have the privilege set, either directly or inherited.
Table 1010. Extension Privileges
Privilege Name Description Required On
Extension.Register
extension
Allows registration of an extension (plug-in). Root vCenter Server
Extension.Unregister
extension
Allows unregistering an extension (plug-in). Root vCenter Server
Extension.Update extension Allows updates to an extension (plug-in). Root vCenter Server
Folder Privileges
Folder privileges control the ability to create and manage folders.
You can set this privilege at dierent levels in the hierarchy. For example, if you set a privilege at the folder
level, you can propagate the privilege to one or more objects within the folder. The object listed in the
Required On column must have the privilege set, either directly or inherited.
Table 1011. Folder Privileges
Privilege Name Description Required On
Folder.Create folder Allows creation of a new folder. Folders
Folder.Delete folder Allows deletion of a folder.
To have permission to perform this operation, a user or group must
have this privilege assigned in both the object and its parent object.
Folders
Folder.Move folder Allows moving a folder.
Privilege must be present at both the source and destination.
Folders
Folder.Rename folder Allows changing the name of a folder. Folders
Global Privileges
Global privileges control global tasks related to tasks, scripts, and extensions.
You can set this privilege at dierent levels in the hierarchy. For example, if you set a privilege at the folder
level, you can propagate the privilege to one or more objects within the folder. The object listed in the
Required On column must have the privilege set, either directly or inherited.
Table 1012. Global Privileges
Privilege Name Description Required On
Global.Act as vCenter
Server
Allows preparation or initiation of a vMotion send operation or a
vMotion receive operation.
Root vCenter Server
Global.Cancel task Allows cancellation of a running or queued task. Inventory object related
to the task
Global.Capacity planning Allows enabling the use of capacity planning for planning
consolidation of physical machines to virtual machines.
Root vCenter Server
vSphere Security
262 VMware, Inc.