VMware Cloud Community
purduecjs
Enthusiast
Enthusiast

Department role/permissions problem solved! Virtual Center vCenter

I was trying to figure out how to assign departments within my organization the ability to fully administer VMs within their own folder, and I hit several obstacles. Given that I couldn't find very strong documentation on either permissions or the messages I was receiving, I'll elaborate below in hopes of helping others that are struggling with a similar problem.

Here are the permissions that ended up working well for me:

Assign the following to Datacenter, Cluster, and each of the hosts independently. DO NOT PROPAGATE if your department admins should not see machines of others

Resource -> Assign Virtual Machine to Resource Pool

*** I defined this as a separate role called something like "VM Managers"

Assign the following to the folder containing the departmental VMs. SET THIS TO PROPAGATE

Global -> Log Event
Global -> Cancel Task
Folder -> Create Folder
Folder -> Delete Folder
Folder -> Move Folder
Datastore -> Browse Datastore (so they can install from ISO)
Virtual Machine -> Inventory **check all**
Virtual Machine -> Interaction **check all**
Virtual Machine -> Configuration **check all EXCEPT Raw Device and Host USB Device**
Virtual Machine -> Provisioning **check all**
Alarms **check all**
Tasks **check all**
Scheduled Task **check all**

*** I defined this as a separate role called something like "Department VM Admin"

The last role was fairly straightforward, but the first part was hanging me up repeatedly. When I would attempt to create a VM as a department I would right-click the folder and select "New Virtual Machine". Everything was ok until "Host / Cluster" at which point I would try to select our Cluster and receive the message:

"Cannot select ClusterName due to insufficient privileges."

Best regards,

Cameron J. Smith

System Administrator, Purdue University

-- Cameron
Reply
0 Kudos
3 Replies
electromagnetic
Contributor
Contributor

Hi, I just registered on these forums to let you know how helpful this post was. I struggled with this for an entire day and couldn't get past being able to browse the cluster without granting access to all the VMs. Thanks so much, also I modified one thing - Datastore - File Management, otherwise you get an error trying to open any of the datastores.

Reply
0 Kudos
PaChilds
Contributor
Contributor

This posts mentioning of the Resource -> Assign Virtual Machine to Resource Pool needing to be set just saved me an afternoon of trial and error. I was having the "Cannot select HostName due to insufficient privileges" problem myself. Thanks

Reply
0 Kudos
dliverpool
Contributor
Contributor

Thank you! That "Assign Virtual machine to Resource Pool" was the one I was looking for!

Reply
0 Kudos