5.5

Table Of Contents
You can also create isolated resources on the shared recovery site and map the resources on the protected
sites to their own dedicated resources on the shared recovery site. You might use this configuration if you
must keep all of the customers' virtual machines separate from each other, for example if all of the
customers belong to different organizations.
Guidelines for Sharing Customer Resources
Follow these guidelines when you configure permissions for sharing customer resources on the shared
recovery site:
n
All customers must have read access to all folders of the vCenter Server on the shared recovery site.
n
Do not give a customer the permission to rename, move, or delete the datacenter or host.
n
Do not give a customer the permission to create virtual machines outside of the customer’s dedicated
folders and resource pools.
n
Do not allow a customer to change roles or assign permissions for objects that are not dedicated to the
customer’s own use.
n
To prevent unwanted propagation of permissions across different organizations’ resources, do not
propagate permissions on the root folder, datacenters, and hosts of the vCenter Server on the shared
recovery site.
Guidelines for Isolating Customer Resources
Follow these guidelines when you configure permissions for isolating customer resources on the shared
recovery site:
n
Assign to each customer a separate virtual machine folder in the vCenter Server inventory.
n
Set permissions on this folder to prevent any other customer from placing their virtual machines in
it. For example, set the Administrator role and activate the propagate option for a customer on that
customer's folder. This configuration prevents duplicate name errors that might otherwise occur if
multiple customers protect virtual machines that have identical names.
n
Place all of the customer's placeholder virtual machines in this folder, so that they can inherit its
permissions.
n
Do not assign permissions to access this folder to other customers.
n
Assign dedicated resource pools, datastores, and networks to each customer, and configure the
permissions in the same way as for folders.
Viewing Tasks and Events in a Shared Recovery Site Configuration
In the Recent Tasks panel of the vSphere Client, users who have permissions to view an object can see tasks
that other users start on that object. All customers can see all of the tasks that other users perform on a
shared resource. For example, all users can see the tasks that run on a shared host, datacenter, or the
vCenter Server root folder.
Events that all of the instances of SRM Server generate on a shared recovery site have identical permissions.
All users who can see events from one instance of SRM Server can see events from all SRM Server instances
that are running on the shared recovery site.
Site Recovery Manager Administration
12 VMware, Inc.