6.7

Table Of Contents
Understanding the Object-Level Permission Model
You authorize a user or group to perform tasks on vCenter objects by using permissions on the object.
The vSphere permission model relies on assigning permissions to objects in the vSphere object
hierarchy. Each permission gives one user or group a set of privileges, that is, a role for the selected
object. For example, a group of users might have the ReadOnly role on one VM and the Administrator
role on another VM.
The following concepts are important.
Permissions Each object in the vCenter Server object hierarchy has associated
permissions. Each permission specifies for one group or user which
privileges that group or user has on the object.
Users and Groups On vCenter Server systems, you can assign privileges only to
authenticated users or groups of authenticated users. Users are
authenticated through vCenter Single Sign-On. Users and groups must be
defined in the identity source that vCenter Single Sign-On uses to
authenticate. Define users and groups using the tools in your identity
source, for example, Active Directory.
Privileges Privileges are fine-grained access controls. You can group those privileges
into roles, which you can then map to users or groups.
Roles Roles are sets of privileges. Roles allow you to assign permissions on an
object based on a typical set of tasks that users perform. Default roles,
such as Administrator, are predefined on vCenter Server and cannot be
changed. Other roles, such as Resource Pool Administrator, are predefined
sample roles. You can create custom roles either from scratch or by cloning
and modifying sample roles. See Create a Custom Role.
Figure 21. vSphere Permissions
Permission
vSphere object
User or group
Role
Privilege
Privilege
Privilege
Privilege
To assign permissions to an object, you follow these steps:
1 Select the object to which you want to apply the permission in the vCenter object hierarchy.
vSphere Security
VMware, Inc. 20