User "administrator@vsphere.local" unable to perform any operation on a specific cluster inside the vCenter server.
search cancel

User "[email protected]" unable to perform any operation on a specific cluster inside the vCenter server.

book

Article ID: 406388

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

  • The local domain user "[email protected]" is unable to perform any operation on a specific cluster inside the vCenter server.
  • For that one specific cluster, the options to add the Host, add a permission for a user in the same cluster or its child objects (ESXi Hosts in the cluster), put the Host in maintenance mode etc are all greyed out. The user is however able to perform all this successfully on other clusters as well as all other objects within the vCenter server.
  • A "test" user with an "administrator" role is able to perform all the operations on the affected cluster and its child objects. 

Environment

VMware vCenter Server 7.x
VMware vCenter Server 8.x

Cause

The TrustedAdmins group or any other group with elevated privileges to manage and administer the vCenter Server and its associated objects have "Administrator" role assigned to them defined in "Global Permissions". Below is how it looks like under normal circumstances.




In case any of these groups have less elevated privileges or the permission isn't defined globally for the affected cluster object, the local domain user "Administrator" is not able to manage it and therefore all the options show greyed out. Below is how it might look in case of a non-working scenario.

 

Resolution

To fix the issue.

  1. Create a test user with "Administrator" role.
  2. Login using the test user and navigate to the affected cluster object.
  3. Remove the incorrect permission for TrustedAdmins from the cluster object.
  4. Once you remove the same, it should automatically inherit the "Administrator" role as "Global Permission" and not as "this object and its associated children" on the specified cluster without having to manually add the permission for the group on the cluster object.
  5. Now login back using the default "administrator" user and you should be able to manage this cluster back again.