vSphere: Minimum User Permissions
Create minimum required roles for provisioning and installing in vSphere
When a user needs permissions less than Admin, a role must be created. The process for configuring a vSphere role with the least permissions for provisioning nodes and installing includes the following steps:
Open a vSphere Client connection to the vCenter Server, described in the Prerequisites.
Select Home > Administration > Roles > Add Role.
Give the new role a name, then select these Privileges:
Cns | ||
Searchable | ||
Datastore | ||
Allocate space | ||
Low level file operations | ||
Host | ||
| ||
Storage partition configuration | ||
Profile-driven storage | ||
Profile-driven storage view | ||
Network | ||
Assign network | ||
Resource | ||
Assign virtual machine to resource pool | ||
Virtual machine | ||
| ||
Add new disk | ||
Add existing disk | ||
Add or remove device | ||
Advanced configuration | ||
Change CPU count | ||
Change Memory | ||
Change Settings | ||
Reload from path | ||
Edit inventory | ||
Create from existing | ||
Remove | ||
Interaction | ||
Power off | ||
Power on | ||
Provisioning | ||
Clone template | ||
Deploy template | ||
Session | ||
ValidateSession |
Add the permission at the highest level and set to propagate the permissions.