Managing global vSphere permissions

View as Markdown

Find out how to manage global vSphere user permissions from the OVHcloud Control Panel

Objective

Global vSphere permissions allow you to define a user's rights on your Hosted Private Cloud service. From the OVHcloud Control Panel, you can enable or disable these options for each user.

This guide explains how to manage these global permissions.

Requirements


OVHcloud Control Panel Access

  • Direct link: VMware vSphere
  • Navigation path: Hosted Private Cloud > Managed VMware vSphere > Select your vSphere service

Instructions

Access the user rights management

  1. From your vSphere service, go to the Users tab.

    Users tab
  2. On the row of the relevant user, open the ... menu and click Edit.

Configure global permissions

In the user edit window, several options correspond to the global permissions.

  1. Enable or disable the options according to the rights you want to grant to the user.

    User rights edit window
  2. Confirm the change.

Available permissions

The user edit window offers the following options:

PermissionDescription
Token validatorAllows the user to validate operations that require a validation token. This permission is generally useful when two-factor authentication (2FA) is enabled on the service, for example as part of certain certifications such as Healthcare Data Hosting (HDS).
IPAllows the user to manage the IP addresses associated with the service.
Failover IPAllows the user to manage the IP Failover addresses associated with the service.
NSX InterfaceGrants access to the NSX network management interface.
Encryption managementAllows the user to manage virtual machine encryption (KMS).

Manage rights by datacenter

In addition to the global service permissions, you can also define rights for each virtual datacenter in your Hosted Private Cloud.

  1. From the Users tab, on the desired user row, open the ... menu and click View/Edit the rights for each DC.

    Users tab and actions menu
  2. On the Manage user rights by datacentre page, locate the datacenter row. Open the ... menu and click Modify rights.

    Manage rights by datacentre
  3. In the Editing rights window, set the rights and confirm.

    Editing rights modal

Rights reference

vSphere access — global user rights on vSphere.

RightDescription
NoneNo access
OperatorReserved for OVHcloud administrators
Read-onlyRead-only access
Read/WriteRead and write access

Access to the VM Network — management rights over the public network section ("VM Network" in vSphere).

RightDescription
NoneNo access
OperatorAllows VMs to be configured on a public network
Read-onlyRead-only access

Access to the V(X)LANs — management rights over the private network section (VXLAN for Hosted Private Cloud, VLAN for SDDC).

RightDescription
NoneNo access
OperatorAllows VMs to be configured on a private network
AdministratorAllows port groups to be managed on the virtual switch (create, modify, delete). SDDC and Premier only
Read-onlyRead-only access

Host and storage management — when enabled, the user can add or delete hosts and storage via the OVHcloud plugin in the vSphere client.

Restricting access to specific vSphere objects

The permissions above apply to the whole service (vSphere cluster) or to a single virtual datacenter. To restrict a user to specific objects in the vSphere inventory — a virtual machine, a datastore or a folder — use the granular rights on vSphere objects.

Go further

For training or technical assistance implementing our solutions, contact your sales representative or visit our Professional Services page to request a quote and have your project analysed by our experts.

Join our community of users.

Was this page helpful?