6.7

Table Of Contents
Distributed Switch Privileges
Distributed Switch privileges control the ability to perform tasks related to the management of Distributed
Switch instances.
You can set this privilege at different levels in the hierarchy. For example, if you set a privilege at the
folder level, you can propagate the privilege to one or more objects within the folder. The object listed in
the Required On column must have the privilege set, either directly or inherited.
Table 139. vSphere Distributed Switch Privileges
Privilege Name Description Required On
Distributed switch.Create Allows creation of a distributed switch. Data centers, Network
folders
Distributed switch.Delete Allows removal of a distributed switch.
To have permission to perform this operation, a user or group must have
this privilege assigned in both the object and its parent object.
Distributed switches
Distributed switch.Host
operation
Allows changing the host members of a distributed switch. Distributed switches
Distributed switch.Modify Allows changing the configuration of a distributed switch. Distributed switches
Distributed switch.Move Allows moving a vSphere Distributed Switch to another folder. Distributed switches
Distributed switch.Network
I/O control operation
Allow changing the resource settings for a vSphere Distributed Switch. Distributed switches
Distributed switch.Policy
operation
Allows changing the policy of a vSphere Distributed Switch. Distributed switches
Distributed switch .Port
configuration operation
Allow changing the configuration of a port in a vSphere Distributed
Switch.
Distributed switches
Distributed switch.Port
setting operation
Allows changing the setting of a port in a vSphere Distributed Switch. Distributed switches
Distributed switch.VSPAN
operation
Allows changing the VSPAN configuration of a vSphere Distributed
Switch.
Distributed switches
ESX Agent Manager Privileges
ESX Agent Manager privileges control operations related to ESX Agent Manager and agent virtual
machines. The ESX Agent Manager is a service that lets you install management virtual machines, which
are tied to a host and not affected by VMware DRS or other services that migrate virtual machines.
You can set this privilege at different levels in the hierarchy. For example, if you set a privilege at the
folder level, you can propagate the privilege to one or more objects within the folder. The object listed in
the Required On column must have the privilege set, either directly or inherited.
vSphere Security
VMware, Inc. 249