Users assigned to the NoAccess role in vCenter still have access
book
Article ID: 429056
calendar_today
Updated On:
Products
VMware vCenter Server
Issue/Introduction
Users assigned to the NoAccess role are still allowed to login to the vCenter and see objects in the infrastructure.
Environment
VMware vCenter Server
Cause
Users is being provided permissions based on a group membership that is assigned to another role
Resolution
Determine what permissions and groups the user is assigned to utilize authz-doctor. The groups that the user is assigned to will be visible in the authz_doctor output.
Check the visible objects that the user can see to verify if any groups that the user is part of have permissions assigned to those objects.
If the user doesn't need to be in that group, you can remove them from the group in Active Directory.
Careful modifying the permissions assigned to the role as it will affect all users assigned to that group/role.