VMware 4817V62 Administration Guide - Page 223

Required Privileges for Common Tasks, Required Privileges, Applicable Role

Page 223 highlights

Chapter 18 Managing Users, Groups, Roles, and Permissions Required Privileges for Common Tasks Many tasks require permissions on more than one object in the inventory. Table 18-2 lists common tasks that require more than one privilege. It lists the privileges required to perform the tasks and, where applicable, the appropriate sample roles. You can use the listed Applicable Roles on the listed inventory objects to grant permission to perform these tasks, or you can create your own roles with the equivalent required privileges. Table 18-2. Required Privileges for Common Tasks Task Required Privileges Applicable Role Create a virtual machine On the destination folder or datacenter: n Virtual Machine.Inventory.Create n Virtual Machine.Configuration.Add New Disk (if creating a new virtual disk) n Virtual Machine .Configuration.Add Existing Disk (if using an existing virtual disk) n Virtual Machine.Configuration.Raw Device (if using a RDM or SCSI pass-through device) Virtual Machine Administrator On the destination host, cluster, or resource pool: Resource.Assign Virtual Machine to Resource Pool Virtual Machine Administrator On the destination datastore or folder containing a datastore: Datastore.Allocate Space Datastore Consumer or Virtual Machine Administrator On the network that the virtual machine will be assigned to: Network.Assign Network Network Consumer or Virtual Machine Administrator Deploy a virtual machine from a template On the destination folder or datacenter: n Virtual Machine.Inventory.Create n Virtual Machine.Configuration.Add New Disk Virtual Machine Administrator On a template or folder of templates: Virtual Machine.Provisioning.Deploy Template Virtual Machine Administrator On the destination host, cluster or resource pool: Resource.Assign Virtual.Machine to Resource Pool Virtual Machine Administrator On the destination datastore or folder of datastores: Datastore.Allocate Space Datastore Consumer or Virtual Machine Administrator On the network that the virtual machine will be assigned to: Network.Assign Network Network Consumer or Virtual Machine Administrator Take a virtual machine snapshot On the virtual machine or a folder of virtual machines: Virtual Machine.State.Create Snapshot Virtual Machine Power User or Virtual Machine Administrator On the destination datastore or folder of datastores: Datastore.Allocate Space Datastore Consumer or Virtual Machine Administrator Move a virtual machine into a resource pool On the virtual machine or folder of virtual machines: n Resource.Assign Virtual Machine to Resource Pool n Virtual Machine.Inventory.Move Virtual Machine Administrator On the destination resource pool: Resource.Assign Virtual Machine to Resource Pool Virtual Machine Administrator VMware, Inc. 223

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364

Required Privileges for Common Tasks
Many tasks require permissions on more than one object in the inventory.
Table 18-2
lists common tasks that require more than one privilege. It lists the privileges required to perform
the tasks and, where applicable, the appropriate sample roles. You can use the listed Applicable Roles on the
listed inventory objects to grant permission to perform these tasks, or you can create your own roles with the
equivalent required privileges.
Table 18-2.
Required Privileges for Common Tasks
Task
Required Privileges
Applicable Role
Create a virtual machine
On the destination folder or datacenter:
n
Virtual Machine.Inventory.Create
n
Virtual Machine.Configuration.Add New Disk
(if
creating a new virtual disk)
n
Virtual Machine .Configuration.Add Existing Disk
(if using an existing virtual disk)
n
Virtual Machine.Configuration.Raw Device
(if using
a RDM or SCSI pass-through device)
Virtual Machine
Administrator
On the destination host, cluster, or resource pool:
Resource.Assign Virtual Machine to Resource Pool
Virtual Machine
Administrator
On the destination datastore or folder containing a
datastore:
Datastore.Allocate Space
Datastore Consumer or
Virtual Machine
Administrator
On the network that the virtual machine will be assigned
to:
Network.Assign Network
Network Consumer or
Virtual Machine
Administrator
Deploy a virtual machine
from a template
On the destination folder or datacenter:
n
Virtual Machine.Inventory.Create
n
Virtual Machine.Configuration.Add New Disk
Virtual Machine
Administrator
On a template or folder of templates:
Virtual Machine.Provisioning.Deploy Template
Virtual Machine
Administrator
On the destination host, cluster or resource pool:
Resource.Assign Virtual.Machine to Resource Pool
Virtual Machine
Administrator
On the destination datastore or folder of datastores:
Datastore.Allocate Space
Datastore Consumer or
Virtual Machine
Administrator
On the network that the virtual machine will be assigned
to:
Network.Assign Network
Network Consumer or
Virtual Machine
Administrator
Take a virtual machine
snapshot
On the virtual machine or a folder of virtual machines:
Virtual Machine.State.Create Snapshot
Virtual Machine Power User
or Virtual Machine
Administrator
On the destination datastore or folder of datastores:
Datastore.Allocate Space
Datastore Consumer or
Virtual Machine
Administrator
Move a virtual machine into a
resource pool
On the virtual machine or folder of virtual machines:
n
Resource.Assign Virtual Machine to Resource Pool
n
Virtual Machine.Inventory.Move
Virtual Machine
Administrator
On the destination resource pool:
Resource.Assign Virtual Machine to Resource Pool
Virtual Machine
Administrator
Chapter 18 Managing Users, Groups, Roles, and Permissions
VMware, Inc.
223