6.7

Table Of Contents
Each solution has a root object in its own object hierarchy. The global root object acts as a parent object
to the root objects for all solutions. You can assign global permissions to users or groups, and decide on
the role for each user or group. The role determines the set of privileges that the user or group has for all
objects in the hierarchy. You can assign a predefined role or create custom roles. See Using Roles to
Assign Privileges. It is important to distinguish between vCenter Server permissions and global
permissions.
vCenter Server
permissions
You usually apply a permission to a vCenter Server inventory object such
as an ESXi host or a virtual machine. When you do, you specify that a user
or group has a set of privileges, called a role, on the object.
Global permissions Global permissions give a user or group privileges to view or manage all
objects in each of the inventory hierarchies in your deployment.
If you assign a global permission and do not select Propagate, the users or
groups associated with this permission do not have access to the objects in
the hierarchy. They only have access to some global functionality such as
creating roles.
Important Use global permissions with care. Verify that you really want to assign permissions to all
objects in all inventory hierarchies.
Add a Global Permission
You can use global permissions to give a user or group privileges for all objects in all inventory
hierarchies in your deployment.
Important Use global permissions with care. Verify that you really want to assign permissions to all
objects in all inventory hierarchies.
Prerequisites
To perform this task, you must have Permissions.Modify permission privileges on the root object for all
inventory hierarchies.
Procedure
1 Click Administration and select Global Permissions in the Access Control area.
2 Click Manage, and click the Add permission icon.
3 Select the user or group that will have the privileges defined by the selected role.
a From the Domain drop-down menu, select the domain for the user or group.
b Type a name in the Search box or select a name from the list.
The system searches user names, group names, and descriptions.
c Select the user or group and click Add.
The name is added to either the Users or Groups list.
vSphere Security
VMware, Inc. 29