Skip to main content

Troubleshooting VMware Account Permissions Errors

Learn how to verify if your VMware user account has read-only and propagate permissions

Written by Omega Team

Prerequisites

You must have admin access to VMware vCenter.

Overview

If OneIQ Pulse is unable to collect data from a VMware environment, the vCenter user account may be missing the required read-only or propagate permissions. This can prevent OneIQ Pulse from displaying datacenter, cluster, host, and virtual machine objects.

When this issue occurs, OneIQ Pulse will display the following error message:

Username and password are likely correct, but the user does not have permission to login. Ensure that the user is in a group, and the user/group have propagate permissions.



Use the steps below to verify that the account can access vCenter and that the correct permissions are assigned.

Solution

Step 1 – Verify the account can access vCenter

  1. Log in to the vCenter web interface using the same user account entered in OneIQ Pulse.

  2. Confirm that datacenter, cluster, host, and virtual machine objects are visible. If these objects are not displayed, the account may be missing the required propagate permissions.

Step 2 – Confirm read-only and propagate permissions

  1. Log in to vCenter with admin privileges.

  2. Go to Administration. Under Access Control, select Roles.

  3. Select the Read-only role and click Usage.

  4. Under the Usage tab, confirm that the user account is listed, or that it belongs to a group that is listed.

    vSphere Client Roles screen showing the Read-only role selected and the Usage tab listing assigned user accounts

    Step 3 – Verify Global Permissions

    1. Go to Administration. Under Access Control, select Global Permissions.

    2. Select the user account and click Edit.

    3. Confirm that the Read-only role is assigned and that Propagate to children is checked.

    4. Click OK.

Did this answer your question?