Unable to Create Limited Role for Permission Management in vCenter - Security Limitation
book
Article ID: 382666
calendar_today
Updated On:
Products
VMware vCenter Server
Issue/Introduction
Users may attempt to create a custom role in vCenter with only permissions management capabilities (modify permissions, privileges, roles) but encounter "Permission to perform this operation was denied" errors when the account attempts to modify permissions.
Environment
- vCenter Server - Custom role with permissions: - Modify Permission - Modify Privilege - Modify Role - Reassign Role Permissions
Cause
This limitation is by design. For security purposes, accounts that manage permissions must possess all permissions they intend to assign or modify for other accounts. This prevents privilege escalation exploits where limited accounts could grant higher permissions than they possess.
Resolution
Use an administrator account to manage permissions
If a dedicated permissions management account is required, it must be granted all permissions that it needs to manage for other accounts
Additional Information
There is no workaround for creating a limited-permission account that can only modify permissions
This security measure helps prevent unauthorized privilege escalation
Consider implementing change control processes and audit logging if multiple administrators need to manage permissions