VMware Cloud Community
jrmunday
Commander
Commander

VDP Permissions

Hi All,

I'm having a problem understanding the VDP permissions in vCenter, and was hoping there is a quick fix or reasonable explanation for what I'm seeing. The issue I have is that VDP only works when logged in as the SSO administrator, and not for other users. For Other users, I don't see the Navigator menu item but I do see the VDP icon in the home view. When clicking on the icon, I get the following error;

Error Stack

---------------------

Error: Invalid domain view id: com.vmware.vdp2.mainapplication

  at com.vmware.vsphere.client.views.app::AppViewMediator/showDomainView()

  at com.vmware.vsphere.client.views.app::AppViewMediator/activateExtension()

  at com.vmware.ui.navigation::NavigationManager/onExtensionHostsRetrieved()

  at com.vmware.extensionfw::CallbackUtil$/callback()

  at com.vmware.extensionfw::ExtensionManager/getExtensionHosts()

  at com.vmware.ui.navigation::NavigationManager/onNavigationRequest()

  at EventFunctor/notifyTarget()

  at EventFunctor/onEvent()

  at flash.events::EventDispatcher/dispatchEvent()

  at com.vmware.frinje::EventBus/dispatchEvent()

  at com.vmware.frinje::EventBus/onEvent()

  at flash.events::EventDispatcher/dispatchEvent()

  at mx.core::UIComponent/dispatchEvent()

  at com.vmware.vsphere.client.views.controlcenter::ControlCenterShortcutItemRenderer/onClick()

  at com.vmware.vsphere.client.views.controlcenter::ControlCenterShortcutItemRenderer/___ControlCenterShortcutItemRenderer_ItemRenderer1_click()

Looking at this documentation

https://pubs.vmware.com/vsphere-60/topic/com.vmware.ICbase/PDF/vmware-data-protection-administration...

I can see the following sections (page 24 and 193);

Before the vCenter user account can be used with VDP, or before the SSO admin user can be used with VDP,

you must add these users as administrator on the vCenter root node. Users who inherit permissions from

group roles are not valid.

NOTE In high-security environments, you can restrict the vCenter user account permissions required to

configure and administer the VDP appliance. The account permission categories are listed in “Minimum

Required vCenter User Account Permissions” on page 193.

I also read up online and saw a blog article or KB reference that these permissions need to be set on all vCenter servers if using Enhanced Linked mode.

Has anyone done this before, or have any guidance on what needs to be done to resolve this. I do have a support case open with VMware, but am reaching out to the community as well - thanks!

Cheers,

Jon

vExpert 2014 - 2022 | VCP6-DCV | http://www.jonmunday.net | @JonMunday77
Tags (2)
0 Kudos
0 Replies