You can either assign PingFederate users to a vCenter Server group or assign inventory-level and global permissions to PingFederate users.

The minimum permission required for a PingFederate user to log in is Read-Only.

Prerequisites

Procedure

  1. To assign PingFederate users to a group, see Add Members to a vCenter Single Sign-On Group.
  2. To assign inventory-level and global permissions to PingFederate users, see the topic about managing permissions for vCenter Server components in the vSphere Security documentation.
  3. After assigning a PingFederate user permissions, verify that the user can log in.