After you create users and groups and define roles, you must assign the users and groups and their roles to the relevant inventory objects. You can assign the same propagating permissions to multiple objects simultaneously by moving the objects into a folder and setting the permissions on the folder.

When you assign permissions, user and group names must match Active Directory precisely, including case. If you upgraded from earlier versions of vSphere, check for case inconsistencies if you experience problems with groups.


On the object whose permissions you want to modify, you must have a role that includes the Permissions.Modify permission privilege.


  1. Browse to the object for which you want to assign permissions in the vSphere Client object navigator.
  2. Click the Permissions tab.
  3. Click the Add Permission icon.
  4. Select the user or group that will have the privileges defined by the selected role.
    1. From the User drop-down menu, select the domain for the user or group.
    2. Type a name in the Search box.
      The system searches user names and group names.
    3. Select the user or group.
  5. Select a role from the Role drop-down menu.
  6. (Optional) To propagate the permissions, select the Propagate to children check box.
    The role is applied to the selected object and propagates to the child objects.
  7. Click OK .