6.7

Table Of Contents
n
Moving an object in the inventory hierarchy requires appropriate privileges on the object itself, the
source parent object (such as a folder or cluster), and the destination parent object.
n
Each host and cluster has its own implicit resource pool that contains all the resources of that host or
cluster. Deploying a virtual machine directly to a host or cluster requires the Resource.Assign
Virtual Machine to Resource Pool privilege.
Table 24. Required Privileges for Common Tasks
Task Required Privileges Applicable Role
Create a virtual machine On the destination folder or data center:
n
Virtual machine .Inventory.Create new
n
Virtual machine.Configuration.Add new disk (if creating a new virtual
disk)
n
Virtual machine.Configuration.Add existing disk (if using an existing
virtual disk)
n
Virtual machine.Configuration.Raw device (if using an RDM or SCSI
pass-through device)
Administrator
On the destination host, cluster, or resource pool:
Resource.Assign virtual machine to resource pool
Resource pool
administrator or
Administrator
On the destination datastore or the folder that contains the datastore:
Datastore.Allocate space
Datastore
Consumer or
Administrator
On the network that the virtual machine will be assigned to:
Network.Assign network
Network
Consumer or
Administrator
Power on a virtual machine On the data center in which the virtual machine is deployed:
Virtual machine .Interaction .Power On
Virtual Machine
Power User or
Administrator
On the virtual machine or folder of virtual machines:
Virtual machine .Interaction .Power On
Deploy a virtual machine from a
template
On the destination folder or data center:
n
Virtual machine .Inventory.Create from existing
n
Virtual machine.Configuration.Add new disk
Administrator
On a template or folder of templates:
Virtual machine .Provisioning.Deploy template
Administrator
On the destination host, cluster or resource pool:
Resource.Assign virtual machine to resource pool
Administrator
On the destination datastore or folder of datastores:
Datastore.Allocate space
Datastore
Consumer or
Administrator
On the network that the virtual machine will be assigned to:
Network.Assign network
Network
Consumer or
Administrator
Take a virtual machine
snapshot
On the virtual machine or a folder of virtual machines:
Virtual machine .Snapshot management. Create snapshot
Virtual Machine
Power User or
Administrator
vSphere Security
VMware, Inc. 36