6.7

Table Of Contents
2 Select the group or user that should have privileges on the object.
3 Select individual privileges or a role, that is a set of privileges, that the group or user should have on
the object.
By default, permissions propagate, that is the group or user has the selected role on the selected
object and its child objects.
vCenter Server offers predefined roles, which combine frequently used privilege sets. You can also create
custom roles by combining a set of roles.
Permissions must often be defined on both a source object and a destination object. For example, if you
move a virtual machine, you need privileges on that virtual machine, but also privileges on the destination
data center.
See the following information.
To find out about... See...
Creating custom roles. Create a Custom Role
All privileges and the objects to which you can apply the
privileges
Chapter 13 Defined Privileges
Sets of privileges that are required on different objects for
different tasks.
Required Privileges for Common Tasks
The permissions model for standalone ESXi hosts is simpler. See Assigning Privileges for ESXi Hosts.
Hierarchical Inheritance of Permissions
When you assign a permission to an object, you can choose whether the permission propagates down
the object hierarchy. You set propagation for each permission. Propagation is not universally applied.
Permissions defined for a child object always override the permissions that are propagated from parent
objects.
The figure illustrates the inventory hierarchy and the paths by which permissions can propagate.
Note Global permissions support assigning privileges across solutions from a global root object. See
Global Permissions.
vSphere Security
VMware, Inc. 21