6.7

Table Of Contents
Add Permissions for Tags and Tag Categories
You can manage the user privileges for working with tags and categories. The procedure for assigning
permission to tags is the same as the procedure for tag categories.
You can set permissions on common tag operations to manage the operations over the inventory objects.
You must have vSphere administrator credentials to set and manage permissions for tags. When you
create a tag, you can specify which users and groups can operate with that tag. For example, you can
grant administrative rights only to administrators and set read-only permissions for all other users or
groups.
Permissions for tags work similar to permissions for vCenter Server inventory objects. See vSphere
Security for more background information.
Procedure
1 In the vSphere Client, select Menu > Tasks & Custom Attributes.
2 Select a tag from the list, right-click the tag, and select Add Permission.
You see a list with all default permissions for the selected tag.
3 Click the Add icon to add a permission to the existing list.
The Add permission dialog box appears.
4 In the Users and Groups pane, click Add, select all the users and groups you want to add, and click
OK.
5 (Optional) Select a user or a group from the list and select a role from the Assigned Role list.
6 (Optional) Select Propagate to children to propagate the privileges to the children of the assigned
inventory object.
7 Click OK to save the new tag permission.
Tagging Best Practices
Incorrect tagging can lead to replication errors. To avoid these errors, diligently follow best practices when
tagging objects.
When working with tags in multiple node situations, expect replication delays between the nodes
(generally 30 seconds to 2 minutes depending on your setup). Follow these best practices to avoid
replication errors:
n
After creating a tag, if you immediately assign that tag to a local object, assign it from the
management node where you created the tag.
n
After creating a tag, if you immediately assign that tag to a remote object, assign it from the
management node to which the object is local. Depending on your environment setup, allow for
replication time to propagate the new tag before you use the tag.
vCenter Server and Host Management
VMware, Inc. 79