6.5.1

Table Of Contents
Prerequisites
Verify that you are logged in as a user with Administrator privileges.
Procedure
1 Log in to vCenter Server with the vSphere Web Client.
2 Select Home, click Administration, and click Roles.
3 Select a role, and click the Clone role action icon.
4 Type a name for the cloned role.
5 Select or deselect privileges for the role and click OK.
Edit a Role
When you edit a role, you can change the privileges selected for that role. When completed, these
privileges are applied to any user or group that is assigned the edited role.
You can create or edit a role on a vCenter Server system that is part of the same vCenter Single Sign-On
domain as other vCenter Server systems. The VMware Directory Service (vmdir) propagates the role
changes that you make to all other vCenter Server systems in the group. Assignments of roles to specific
users and objects are not shared across vCenter Server systems.
Prerequisites
Verify that you are logged in as a user with Administrator privileges.
Procedure
1 Log in to vCenter Server with the vSphere Web Client.
2 Select Home, click Administration, and click Roles.
3 Select a role and click the Edit role action button.
4 Select or deselect privileges for the role and click OK.
Best Practices for Roles and Permissions
Use best practices for roles and permissions to maximize the security and manageability of your
vCenter Server environment.
VMware recommends the following best practices when configuring roles and permissions in your
vCenter Server environment:
n
Where possible, assign a role to a group rather than individual users.
n
Grant permissions only on the objects where they are needed, and assign privileges only to users or
groups that must have them. Use the minimum number of permissions to make it easier to
understand and manage your permissions structure.
vSphere Security
VMware, Inc. 36