6.7

Table Of Contents
d (Optional) Click Check Names to verify that the user or group exists in the identity source.
e Click OK.
4 Select a role from the Assigned Role drop-down menu.
The roles that are assigned to the object appear in the menu. The privileges contained in the role are
listed in the section below the role title.
5 Decide whether to leave the Propagate to children check box selected.
If you assign a global permission and do not select Propagate, the users or groups associated with
this permission do not have access to the objects in the hierarchy. They only have access to some
global functionality such as creating roles.
6 Click OK.
Permissions on Tag Objects
In the vCenter Server object hierarchy, tag objects are not children of vCenter Server but are created at
the vCenter Server root level. In environments with multiple vCenter Server instances, tag objects are
shared across vCenter Server instances. Permissions for tag objects work differently than permissions for
other objects in the vCenter Server object hierarchy.
Only Global Permissions or Permissions Assigned to the Tag Object Apply
If you grant permissions to a user on a vCenter Server inventory object, such as a virtual machine, that
user can perform the tasks associated with the permission. However, the user cannot perform tag
operations on the object.
For example, if you grant the Assign vSphere Tag privilege to user Dana on host TPA, that permission
does not affect whether Dana can assign tags on host TPA. Dana must have the Assign vSphere Tag
privilege at the root level, that is, a global permission, or must have the privilege for the tag object.
Table 21. How Global Permissions and Tag Object Permissions Aect What Users Can Do
Global Permission Tag-Level Permission
vCenter Server Object-
Level Permission Effective Permission
No tagging privileges assigned. Dana has Assign or
Unassign vSphere Tag
privileges for the tag.
Dana has Delete vSphere
Tag privileges on ESXi host
TPA.
Dana has Assign or Unassign
vSphere Tag privileges for the
tag.
Dana has Assign or Unassign
vSphere Tag privileges.
No privileges assigned for the
tag.
Dana has Delete vSphere
Tag privileges on ESXi host
TPA.
Dana has Assign or Unassign
vSphere Tag global privileges.
That includes privileges at the
tag level.
No tagging privileges assigned. No privileges assigned for the
tag.
Dana has Assign or
Unassign vSphere Tag
privileges on ESXi host TPA.
Dana does not have tagging
privileges on any object,
including host TPA.
vSphere Security
VMware, Inc. 30