VMware vCenter Roles and Permissions
  • 26 Oct 2022
  • Dark
    Light

VMware vCenter Roles and Permissions

  • Dark
    Light

Article Summary

Introduction

In order for the Cohesity platform to protect Virtual Machines hosted within VMware a privileged account is leveraged. This account is utilized by various processes to create snapshots, create VMs, and a number of different operations for backup and restore functionality. Without an account with the proper permissions, the Cohesity system will not be able to perform any backups against a VMware source or may encounter intermittent hard-to-track errors if the permissions only slightly differ.


The following table is accurate as of the permissions required for Cohesity version 6.6.0d:

Privilege LevelPermissions
Cryptographic operationsAdd Disk
Direct Access
DatastoreAllocate space
Move datastore
Browse datastore
Remove file
Low-level file operations
Configure datastore
FolderCreate folder
Delete folder
GlobalEnableMethods
DisableMethods
Log event
Licenses
Manage custom attributes
Set custom attribute
Host - ConfigurationStorage partition configuration
Maintenance
Query patch
NetworkAssign network
ResourceAssign a virtual machine to a resource pool
Migrate powered-off virtual machine
Migrate powered on virtual machine
SessionView and stop sessions
vAppAdd virtual machine
Assign resource pool
Unregister
VM - ConfigurationAcquire disk lease
Add existing disk
Add new disk
Add or remove a device
Advanced configuration
Change Settings
Change Swapfile placement
Configure Raw device
Remove disk
Toggle disk change tracking
Rename
VM - Guest OperationsGuest operation modifications
Guest operation program execution
Guest operation queries
VM - Edit InventoryCreate new
Register
Remove
Unregister
VM - InteractionGuest operating system management by VIX API
Power on
Power off
VM - ProvisioningAllow disk access
Allow read-only disk access
Allow virtual machine download
VM - Snapshot managementCreate snapshot
Remove snapshot
Revert snapshot
VM storage policiesUpdate
View
vSphere TaggingAssign or unassign tag

Was this article helpful?