Administrator cannot assign Add Permission to an object in the vSphere Web Client
search cancel

Administrator cannot assign Add Permission to an object in the vSphere Web Client

book

Article ID: 342351

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

Symptoms:
  • You see the error:

    Permission to perform this operation was denied. You do not hold privilege "System -> Read" on folder "Datacenters"


Environment

VMware vCenter Server 4.1.x
VMware vCenter Server 4.0.x
VMware vCenter Server 5.0.x
VMware vCenter Server 6.0.x

Cause

This issue occurs when privileges to retrieve the list of all users from the parent object are not defined.

System call retrieves the list of all users from the parent object. Obtaining this list (using the system call) requires privileges in the parent object. If privileges are not defined in the parent object, the call (and the attempt to add the permission) fails.

Resolution

To resolve this issue, assign the Read-only role from the vSphere Web Client object navigator.

To assign the Read-only role to the administrator from the vSphere Web Client object navigator:
  1. Browse to the object in the vSphere Web Client object navigator.
  2. Click the Manage tab and select Permissions.
  3. Click Add Permission.
  4. Click Add.
  5. Select Domain from the Domain dropdown.
  6. Select user and click Add.

    Note: (Optional) Click Check Names to verify that the user or group exists in the database.

  7. Click OK.

    You can see that user is pre-selected and the default Assigned Role is Read-only.

  8. To propagate the privileges to the child objects of the assigned inventory object, select Propagate.
  9. Click OK.