6.5.1

Table Of Contents
ESX Agent Manager Privileges
ESX Agent Manager privileges control operations related to ESX Agent Manager and agent virtual
machines. The ESX Agent Manager is a service that lets you install management virtual machines, which
are tied to a host and not affected by VMware DRS or other services that migrate virtual machines.
You can set this privilege at different levels in the hierarchy. For example, if you set a privilege at the
folder level, you can propagate the privilege to one or more objects within the folder. The object listed in
the Required On column must have the privilege set, either directly or inherited.
Table 1110. ESX Agent Manager
Privilege Name Description Required On
ESX Agent
Manager.Config
Allows deployment of an agent virtual machine on a host or cluster. Virtual machines
ESX Agent
Manager.Modify
Allows modifications to an agent virtual machine such as powering off or
deleting the virtual machine.
Virtual machines
ESX Agent View.View Allows viewing of an agent virtual machine. Virtual machines
Extension Privileges
Extension privileges control the ability to install and manage extensions.
You can set this privilege at different levels in the hierarchy. For example, if you set a privilege at the
folder level, you can propagate the privilege to one or more objects within the folder. The object listed in
the Required On column must have the privilege set, either directly or inherited.
Table 1111. Extension Privileges
Privilege Name Description Required On
Extension.Register
extension
Allows registration of an extension (plug-in). Root vCenter Server
Extension.Unregister
extension
Allows unregistering an extension (plug-in). Root vCenter Server
Extension.Update
extension
Allows updates to an extension (plug-in). Root vCenter Server
Folder Privileges
Folder privileges control the ability to create and manage folders.
You can set this privilege at different levels in the hierarchy. For example, if you set a privilege at the
folder level, you can propagate the privilege to one or more objects within the folder. The object listed in
the Required On column must have the privilege set, either directly or inherited.
vSphere Security
VMware, Inc. 235