6.1

Table Of Contents
Users Gain Access to Virtual Machines After Configuring Temporary
Placeholder Mappings
Users who complete temporary placeholder mappings when the protected site is unavailable might gain
access to virtual machines that they should not.
Problem
The protected site is unavailable during a disaster recovery and Site Recovery Manager creates temporary
placeholder mappings. The user who runs the recovery plan completes the temporary placeholder
mappings and reruns the plan. After the recovery, the user has access to virtual machines on the recovery
site that they did not have permission to access on the protected site.
n
A user runs a disaster recovery when the protected site is unavailable.
n
The user does not have permission to access all of the inventory objects on the protected site.
n
Site Recovery Manager detects missing mappings, and creates temporary placeholder mappings that
include objects on the protected site that the user does not have permission to access.
n
The user configures the target mappings from the objects on the protected site to objects on the recovery
site to which they do have access.
n
After the recovery, because the recovered virtual machines use resources on the recovery site that the
user has permission to access, the user can access virtual machines that they did not have permission to
access when those virtual machines were on the protected site.
Cause
If the protected site is unavailable, Site Recovery Manager cannot perform permission checks on inventory
objects on the protected site before it uses them to create temporary placeholder mappings.
Solution
Verify that users who have permission to run recovery plans also have permission to access all of the objects
on both sites.
Configure Inventory Mappings
Inventory mappings provide default objects in the inventory on the recovery site for the recovered virtual
machines to use when you run recovery.
For array-based protection and vSphere Replication protection, if you configure site-wide inventory
mappings before you create protection groups, you do not have to configure protection individually on each
virtual machine when you create a protection group. Site Recovery Manager applies the site-wide mappings
to all virtual machines in an array-based replication protection group or a vSphere Replication protection
group at the moment that you create the protection group.
When you use storage policy protection, Site Recovery Manager applies inventory mappings at the moment
that a recovery plan runs. You cannot configure protection individually on the virtual machines in a storage
policy protection group. As a consequence, you must configure site-wide inventory mappings if you use
storage policy protection.
Procedure
1 In the vSphere Web Client, click Site Recovery > Sites, and select a site.
Chapter 3 Configuring Mappings
VMware, Inc. 37