6.0.3

Table Of Contents
Table 1012. Global Privileges (Continued)
Privilege Name Description Required On
Global.Diagnostics Allows retrieval of a list of diagnostic les, log header, binary les, or
diagnostic bundle.
To avoid potential security breaches, limit this privilege to the vCenter
Server Administrator role.
Root vCenter Server
Global.Disable methods Allows servers for vCenter Server extensions to disable certain
operations on objects managed by vCenter Server.
Root vCenter Server
Global.Enable methods Allows servers for vCenter Server extensions to enable certain
operations on objects managed byvCenter Server.
Root vCenter Server
Global.Global tag Allows adding or removing global tags. Root host or vCenter
Server
Global.Health Allows viewing the health of vCenter Server components. Root vCenter Server
Global.Licenses Allows viewing installed licenses and adding or removing licenses. Root host or vCenter
Server
Global.Log event Allows logging a user-dened event against a particular managed
entity.
Any object
Global.Manage custom

Allows adding, removing, or renaming custom eld denitions. Root vCenter Server
Global.Proxy Allows access to an internal interface for adding or removing
endpoints to or from the proxy.
Root vCenter Server
Global.Script action Allows scheduling a scripted action in conjunction with an alarm. Any object
Global.Service managers
Allows use of the resxtop command in the vSphere CLI.
Root host or vCenter
Server
Global.Set custom  Allows viewing, creating, or removing custom aributes for a
managed object.
Any object
Global. Allows reading and modifying runtime vCenter Server conguration
seings.
Root vCenter Server
Global.System tag Allows adding or removing system tags. Root vCenter Server
Host CIM Privileges
Host CIM privileges control the use of CIM for host health monitoring.
You can set this privilege at dierent levels in the hierarchy. For example, if you set a privilege at the folder
level, you can propagate the privilege to one or more objects within the folder. The object listed in the
Required On column must have the privilege set, either directly or inherited.
Table 1013. Host CIM Privileges
Privilege Name Description Required On
Host.CIM.CIM Interaction Allow a client to obtain a ticket to use for CIM services. Hosts
Host Configuration Privileges
Host conguration privileges control the ability to congure hosts.
You can set this privilege at dierent levels in the hierarchy. For example, if you set a privilege at the folder
level, you can propagate the privilege to one or more objects within the folder. The object listed in the
Required On column must have the privilege set, either directly or inherited.
Chapter 10 Defined Privileges
VMware, Inc. 263