6.0

Table Of Contents
Managing ESXi Roles in the VMware Host Client
ESXi grants access to objects only to users who are assigned permissions for the object. When you assign a
user permissions for the object, you do so by pairing the user with a role. A role is a predened set of
privileges.
ESXi hosts provide three default roles, and you cannot change the privileges associated with these roles.
Each subsequent default role includes the privileges of the previous role. For example, the Administrator
role inherits the privileges of the Read Only role. Roles that you create do not inherit privileges from any of
the default roles.
You can create custom roles by using the role-editing dunctions in the VMware Host Client to create
privilege sets that match your user needs. Also, the roles you create directly on a host are not accessible in
vCenter Server. You can work with these roles only if you log in to the host directly from the
VMware Host Client.
N When you add a custom role and do not assign any privileges to it, the role is created as a read-only
role with the System.Anonymous, System.View, and System.Read system-dened privilege.
If you manage an ESXi host through vCenter Server, maintaining custom roles in the host and
vCenter Server can result in confusion and misuse. In this type of conguration, maintain custom roles only
in vCenter Server.
You can create host roles and set permissions through a direct connection to the ESXi host with the
VMware Host Client.
Add a Role in the VMware Host Client
You can create roles to suit the access control needs of your environment.
Prerequisites
Verify that you are logged in as a user with Administrator privileges, such as root or vpxuser.
Procedure
1 Click Manage in the VMware Host Client inventory and click Security & Users.
2 Click Roles.
3 Click Add role.
4 Enter a name for the new role.
5 Select privileges from the list to associate with the new role and click Add.
Update a Role in the VMware Host Client
When you edit a role, you can change the privileges selected for that role. When complete, these privileges
are applied to any user or group that is assigned the edited role.
Prerequisites
Verify that you are logged in as a user with Administrator privileges, such as root or vpxuser.
Procedure
1 Click Manage in the VMware Host Client inventory and click Security & Users.
2 Click Roles.
3 Select a role from the list and click Edit role.
4 Update the role details and click Save.
vSphere Single Host Management - VMware Host Client
20 VMware, Inc.