Administrative User for assigned cluster Receives "Unauthorized" Error in Host Updates>Images Tab
book
Article ID: 425552
calendar_today
Updated On:
Products
VMware vCenter Server
Issue/Introduction
User has Administrator rights on a specific Cluster.
User receives An unexpected error has occurred: Unauthorized when clicking the Updates>Images tab.
/var/log/vmware/vlcm/vlcm.log contains: User ... does not have privileges VcLifecycle.View on Folder:group-d1
User is also unable to view the Image Depot in Lifecycle Manager and is greeted with "You do not have the required privilege to view Image Depot." instead.
Environment
vCenter Server 8.0U3
Cause
The vSphere Lifecycle Manager plugin requires global visibility to load its interface. The user lacks the VcLifecycle.View privilege at the vCenter Root object (group-d1) and the ability to read settings for lifecycle manager.
The Image Remediation may show Unauthorized without the Image Remediation Privilege.
Resolution
Create a custom role (e.g., "vLCM Global View") with the privileges VMware vSphere Lifecycle Manager > General Privileges > Read; VMware vSphere Lifecycle Manager > Settings Privileges > Read; VMware vSphere Lifecycle Manager > Image Remediation Privileges > Read.
Assign this role to the desired user or group at the vCenter Server level.
IMPORTANT: Ensure "Propagate to children" is Unchecked.