Virtual machine privileges
If the user that is associated with the provider is not assigned to the Administrator role for an inventory object, the user must be assigned to a role that has the following required privileges. Ensure that the privileges are propagated to child objects. For instructions for adding a permission to an inventory object, see the Add a Permission to an Inventory Object page .
A test feature is available to verify that a user account has the required VMware privileges. Follow the instructions in Testing a vCenter Server user account for required privileges to view the VMware privileges that are associated with the user account.
| vCenter Server Object | Required Privileges |
|---|---|
| Alarm |
|
| Cryptographic Operations (6.5, 6.7, 7.0, and 8.0) |
|
| Datastore |
|
| Distributed switch |
|
| Folder |
|
| Global |
|
| Host > Configuration |
|
|
vSphere Tagging (6.5, 6.7, 7.0, and 8.0) |
|
| Network |
|
| Resource |
|
| Virtual Machine Change > Configuration |
|
| Virtual Machine > Guest Operations |
|
| Virtual Machine > Interaction |
|
| Virtual Machine > Inventory |
|
| Virtual Machine > Provisioning |
|
| Virtual Machine > Snapshot management |
|
| vApp |
|