5.5

Table Of Contents
7 Select Propagate to Child Objects to apply the selected role to all of the child objects of the inventory
objects that this role can affect.
For example, if a role contains privileges to modify folders, selecting this option extends the privileges
to all the virtual machines in a folder. You might deselect this option to create a more complex
hierarchy of permissions. For example, deselect this option to override the permissions that are
propagated from the root of a certain node from the hierarchy tree, but without overriding the
permissions of the child objects of that node.
8 Click OK to assign the role and its associated privileges to the user or user group.
9 Repeat Step 1 through Step 8 to assign roles and privileges to the users or user groups on the other SRM
site.
You assigned a given SRM role to a user or user group. This user or user group has privileges to perform the
actions that the role defines on the objects on the SRM site that you configured.
Example: Combining SRM Roles
You can assign only one role to a user or user group. If a user who is not a vCenter Server administrator
requires the privileges of more than one SRM role, you can create multiple user groups. For example, a user
might require the privileges to manage recovery plans and to run recovery plans.
1 Create two user groups.
2 Assign the SRM Recovery Plans Administrator role to one group.
3 Assign the SRM Recovery Administrator role to the other group.
4 Add the user to both user groups.
By being a member of groups that have both the SRM Recovery Plans Administrator and the SRM Recovery
Administrator roles, the user can manage recovery plans and run recoveries.
SRM Roles Reference
SRM includes a set of roles. Each role includes a set of privileges, which allow users with those roles to
complete different actions.
Roles can have overlapping sets of privileges and actions. For example, the SRM Administrator role and the
SRM Protection Groups Administrator have the Create privilege for protection groups. With this privilege,
the user can complete one aspect of the set of tasks that make up the management of protection groups.
Assign roles to users on SRM objects consistently on both sites, so that protected and recovery objects have
identical permissions.
All users must have at least the System.Read privilege on the root folders of vCenter Server and the SRM
root nodes on both sites.
Site Recovery Manager Administration
14 VMware, Inc.