6.5.1

Table Of Contents
The administrator of the vCenter Single Sign-On domain,
administrator@vsphere.local by default, the root user, and vpxuser are
assigned the Administrator role by default. Other users are assigned the No
Access role by default.
Read Only Role Users with the Read Only role for an object are allowed to view the state of
the object and details about the object. For example, users with this role
can view virtual machine, host, and resource pool attributes, but cannot
view the remote console for a host. All actions through the menus and
toolbars are disallowed.
Best practice is to create a user at the root level and assign the Administrator role to that user. After
creating a named user with Administrator privileges, you can remove the root user from any permissions
or change its role to No Access.
Create a Custom Role
You can create vCenter Server custom roles to suit the access control needs of your environment.
You can create or edit a role on a vCenter Server system that is part of the same vCenter Single Sign-On
domain as other vCenter Server systems. The VMware Directory Service (vmdir) propagates the role
changes that you make to all other vCenter Server systems in the group. Assignments of roles to specific
users and objects are not shared across vCenter Server systems.
Prerequisites
Verify that you are logged in as a user with Administrator privileges.
Procedure
1 Log in to vCenter Server with the vSphere Web Client.
2 Select Home, click Administration, and click Roles.
3 Click the Create role action (+) button.
4 Type a name for the new role.
5 Select privileges for the role and click OK.
Clone a Role
You can make a copy of an existing role, rename it, and edit it. When you make a copy, the new role is
not applied to any users or groups and objects. You must assign the role to users or groups and objects.
You can create or edit a role on a vCenter Server system that is part of the same vCenter Single Sign-On
domain as other vCenter Server systems. The VMware Directory Service (vmdir) propagates the role
changes that you make to all other vCenter Server systems in the group. Assignments of roles to specific
users and objects are not shared across vCenter Server systems.
vSphere Security
VMware, Inc. 35