5.5

Table Of Contents
SRM Privileges, Roles, and
Permissions 1
SRM provides disaster recovery by performing operations for users. These operations involve managing
objects, such as recovery plans or protection groups, and performing operations, such as replicating or
powering off virtual machines. SRM uses roles and permissions so that only users with the correct roles and
permissions can perform operations.
SRM adds several roles to vCenter Server, each of which includes privileges to complete SRM and
vCenter Server tasks. You assign roles to users to permit them to complete tasks in SRM.
Privilege
The right to perform an action, for example to create a recovery plan or to
modify a protection group.
Role
A collection of privileges. Default roles provide the privileges that certain
users require to perform a set of SRM tasks, for example users who manage
protection groups or perform recoveries. A user can have at most one role on
an object, but roles can be combined if the user belongs to multiple groups
that all have roles on the object.
Permission
A role granted to a particular user or user group on a specific object. A user
or user group is also known as a principal. A permission is a combination of
a role, an object, and a principal. For example, a permission is the privilege to
modify a specific protection group.
For information about the roles that SRM adds to vCenter Server and the privileges that users require to
complete tasks, see “SRM Roles Reference,” on page 14.
n
How SRM Handles Permissions on page 10
SRM determines whether a user has permission to perform an operation, such as configuring
protection or running the individual steps in a recovery plan. This permission check ensures the
correct authentication of the user, but it does not represent the security context in which the operation
is performed.
n
SRM and the vCenter Server Administrator Role on page 10
If a user or user group has the vCenter Server administrator role on a vCenter Server instance when
you install SRM, that user or user group obtains all SRM privileges.
n
SRM and vSphere Replication Roles on page 11
When you install vSphere Replication with SRM, the vCenter Server administrator role inherits all of
the SRM and vSphere Replication privileges.
n
Managing Permissions in a Shared Recovery Site Configuration on page 11
You can configure SRM to use with a shared recovery site. The vCenter Server administrator on the
shared recovery site must manage permissions so that each customer has sufficient privileges to
configure and use SRM, but no customer has access to resources that belong to another customer.
VMware, Inc.
9