6.5.1

Table Of Contents
Figure 22. vSphere Inventory Hierarchy
template
host
VDS datastore
cluster
vApp
vApp
vApp
virtual
machine
virtual
machine
resource
pool
resource
pool
virtual
machine
virtual
machine
resource
pool
standard
switch
datastore
cluster
distributed
port group
VM folder host folder
data center
vCenter Server
(vCenter Server instance level)
network
folder
datastore
folder
data center
folder
root object
(global permissions level)
tag category
tag
content library
library item
Most inventory objects inherit permissions from a single parent object in the hierarchy. For example, a
datastore inherits permissions from either its parent datastore folder or parent data center. Virtual
machines inherit permissions from both the parent virtual machine folder and the parent host, cluster, or
resource pool simultaneously.
For example, you can set permissions for a distributed switch and its associated distributed port groups,
by setting permissions on a parent object, such as a folder or data center. You must also select the option
to propagate these permissions to child objects.
vSphere Security
VMware, Inc. 23