ESXi Permissions

Posted on 2014-04-16
Last Modified: 2014-04-16
  I am having an issue with ESXi Permissions sticking. I have a single Host with 2 Resource pools. I have it joined to the Domain and have assigned permissions to 2 users just to one of the Resource Pools. I've done this on the ESXi 5.1 Host itself although it is connected to a vCenter Server. The reason I did this is the Host is in a Remote Office while the vCenter is in the Branch Office. I need the users to access the Host even if the connection to the vCenter Server is down. This seems to be working but every so many weeks the permissions are removed and there is nothing in the log about it. I have to reassign the permissions for the user to access the Resource pool and connect to the Console of the needed Servers.
Question by:CooleyAdmin
  • 3
  • 3
LVL 119
ID: 40003854
How are the permissions being added?

Author Comment

ID: 40003892
I connect directly to the ESXi 5.1 Host and add them directly to the Resource Pool via Right Click Add Permissions. So the 2 Users show as Defined "This Object" The other permissions that are always there are ones assigned on the Entire Host.
LVL 119
ID: 40003938
So you are not connecting to vCenter Server?
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.


Author Comment

ID: 40003953
No I don't add the permission via vCenter Server cause the users connect directly to the host. I have them do this cause if for any reason they loose connection to vCenter I need them still to have the ability to console into the VMs in that Resource Pool. So although the Host is connected to vCenter the permissions are assigned directly to the Host via connecting to the host and assigning the permissions that way.
LVL 119

Accepted Solution

Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 40003976
In that case, vCenter is probably resetting the permissions, because Access control, is supposed to be controlled via vCenter Server.

Adding permissions directly to ESXi Host is not supported when being Managed by vCenter Server, when you connect directly to ESXi, it states this!

So I would either

1. Manage via vCenter Server

2. Manage directly via ESXi Host and vSphere Client (and remove from vCenter Server)

Author Comment

ID: 40003983
Ahh OK I kinda felt that and was concerned that was the case. The permissions stick for awhile but do disappear eventually. Removing it from vCenter is not an option as this is required for our DR Solution. I may need to purchase another License of vCenter and run one in the Branch office or move my vCenter Server to that facility. Thanks for the confirmation

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Last article we focus in how to VMware: How to create and use VMs TAGs – Part 1 so before follow this article and perform the next tasks, you should read the first article how to create the TAG before using them in Veeam Backup Jobs.
HOW TO: Connect to the VMware vSphere Hypervisor 6.5 (ESXi 6.5) using the vSphere (HTML5 Web) Host Client 6.5, and perform a simple configuration task of adding a new VMFS 6 datastore.
This Micro Tutorial steps you through the configuration steps to configure your ESXi host Management Network settings and test the management network, ensure the host is recognized by the DNS Server, configure a new password, and the troubleshooting…
This video shows you how easy it is to boot from ISO images for virtual machines with the ISO images stored on a local datastore on the ESXi host.

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question