2V0-621 · Question #223
An administrator has configured three vCenter Servers and vRealize Orchestrator within a Platform Services Controller domain, and needs to grant a user privileges that span all environments. Which…
The correct answer is A. Assign a Global Permission to the user. Global Permissions in vSphere apply at the root of the global inventory hierarchy and propagate across all vCenter Server instances and registered solutions within the same Platform Services Controller domain.
Question
An administrator has configured three vCenter Servers and vRealize Orchestrator within a Platform Services Controller domain, and needs to grant a user privileges that span all environments. Which statement best describes how the administrator would accomplish this?
Options
- AAssign a Global Permission to the user.
- BAssign a vCenter Permission to the user.
- CAssign vsphere.local membership to the user.
- DAssign an ESXi Permission to the user.
How the community answered
(23 responses)- A83% (19)
- B4% (1)
- C9% (2)
- D4% (1)
Why each option
Global Permissions in vSphere apply at the root of the global inventory hierarchy and propagate across all vCenter Server instances and registered solutions within the same Platform Services Controller domain.
A Global Permission is defined at the top-level root object of the global inventory tree and automatically propagates to every vCenter Server, vRealize Orchestrator instance, and other registered solutions within the same PSC domain. This single assignment spans all three vCenter Servers and the orchestrator simultaneously without requiring per-environment grants. It is the only vSphere permission type specifically designed for multi-solution, cross-environment access control.
A vCenter Permission is scoped to a single vCenter Server's object hierarchy and does not extend access to other vCenter instances or vRealize Orchestrator in the same domain.
Adding a user to vsphere.local grants SSO domain identity membership but does not by itself assign any vCenter privileges or propagate access across the registered environments.
An ESXi Permission is host-local and only governs access to that individual ESXi host's direct management interface, providing no coverage over vCenter Server or vRealize Orchestrator.
Concept tested: Global Permissions spanning multiple vCenter instances via PSC
Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-74F53189-EF41-4AC1-A78E-D25621855800.html
Topics
Community Discussion
No community discussion yet for this question.