6.0

Table Of Contents
Permission Validation
vCenter Server and ESXi hosts that use Active Directory regularly validate users and groups against the
Windows Active Directory domain. Validation occurs whenever the host system starts and at regular
intervals specied in the vCenter Server seings.
For example, if user Smith was assigned permissions and in the domain the users name was changed to
Smith2, the host concludes that Smith no longer exists and removes permissions for that user when the next
validation occurs.
Similarly, if user Smith is removed from the domain, all permissions are removed when the next validation
occurs. If a new user Smith is added to the domain before the next validation occurs, the new user Smith
receives all the permissions the old user Smith was assigned.
Assign Permissions to a User for an ESXi Host in the VMware Host Client
In order to perform particular activities on an ESXi host, a user must have permissions that are associated
with a particular role. In the VMware Host Client you can assign roles to users and give the users the
permissions necessary to perform various tasks on the host.
Procedure
1 Right-click Host in the VMware Host Client inventory and click Permissions.
2 Click Add user.
3 Click the arrow next to the Select a user text box and select the user that you would like to assign a role
to.
4 Click the arrow next to the Select a role text box and select a role from the list.
5 (Optional) Select Propagate to all children.
If you set a permission at a vCenter Server level and propagate it to the children objects, the permission
applies to data centers, folders, clusters, hosts, virtual machines, and other objects in the vCenter Server
instance.
6 Click Add and click Close.
Remove Permissions for a User in the VMware Host Client
Removing a permission for a user does not remove the user from the list of users available. It also does not
remove the role from the list of available items. It removes the user and role pair from the selected inventory
object.
Procedure
1 Right-click Host in the VMware Host Client inventory and click Permissions.
2 Select a user from the list and click Remove user.
3 Click Close.
Assign a User Permissions for a Virtual Machine in the VMware Host Client
Assign a role to a particular user to give that user permissions to perform specic tasks on a virtual machine.
Procedure
1 Click Virtual Machines in the VMware Host Client inventory.
2 Right-click a virtual machine from the list and select Permissions.
Chapter 2 Host Management with the VMware Host Client
VMware, Inc. 25