VcTrusts/VcIdentity privileges control access to various internal APIs and functionality related to trust between vCenter Server systems.

Table 1. VcTrusts/VcIdentity Privileges
Privilege Name in the vSphere Client Description Required On Privilege Name in the API
Create/Update/Delete (Admin privs)

Allows full administrative-level access to various internal APIs and functionality related to trust between vCenter Server systems.

N/A Trust.Administer
Create/Update/Delete (below Admin privs)

Allows reduced administrative access to various internal APIs and functionality related to trust between vCenter Server systems. This privilege restricts creating/updating/deleting VcTrusts/VcIdentity so that the user cannot escalate non-administrator privileges.

N/A Trust.Manage