Create a tailored role with the following permissions in VMware:
Datastore
- Allocate space
- Browse datastore
- Low level file operations
- Remove file
Global
- Licenses
- Log event
-
DisableMethods
-
EnableMethods
Host\Inventory
Host\Local Operations
- Create virtual machine
- Reconfigure virtual machine
Network
Resource
- Assign vApp to resource pool
- Assign virtual machine to resource pool
vApp
- Add virtual machine
- Assign resource pool
- Create
- Delete
- Import
- Move
- Power off
- Power On
- Rename
Virtual machine\ Change Configuration
Virtual Machine\Interaction
- Configure CD media
- Configure floppy media
- Console interaction
- Connect devices
- Power Off
- Power On
- Install VMware Tools
Virtual Machine\Edit Inventory
Virtual Machine\Provisioning
- Allow disk access
- Allow read-only disk access
- Allow virtual machine download
- Allow virtual machine files upload
- Clone template
Virtual Machine\Service Configuration
- Modify service configuration
Virtual Machine\Snapshot Management
If a policy will be used to create an Export of an encrypted virtual machine, please also add all
Cryptographic Operations permissions to the service account.