Tenant Management privileges control aspects of defining and retrieving tenant management entities. (Applies to VMware Cloud on AWS.)

Table 1. Tenant Management Privileges
Privilege Name in the vSphere Client Description Required On Privilege Name in the API
Tenant provisioning operations

Allows defining a set of resources to use for tenant management.

Root folder and each entity currently marked as a service provider. TenantManager.Update
Tenant query operations Allows retrieving the list of tenant management resources. Root folder and each entity currently marked as a service provider. TenantManager.Query