Setting Up Read-Only MOB Access for vCenter

Setting Up Read-Only MOB Access for vCenter

Overview

To enable Cloudmon to monitor VMware vCenter, a user account with Read-Only access is required. This ensures Cloudmon can retrieve inventory, performance, and health metrics without making any changes to the vCenter environment. This article outlines the steps to assign the necessary permissions securely and correctly.

Prerequisites

  • vCenter administrative access

  • Pre-created user accounts and groups in the relevant domain (e.g., India\Domain\user or Dubai\Domain\user)

Steps to Assign Read-Only Access

  1. Login to the vSphere Client

    • Open a browser and go to:
      https://<vcenter-IP>/ui

    • Replace <vcenter-IP> with your actual vCenter IP address.

  2. Navigate to Global Permissions

    • From the main menu, go to:
      MenuAdministrationAccess ControlGlobal Permissions

  3. Add a User

    • Click Add.

    • Select the appropriate domain (e.g., India or Dubai).

    • Search and select the user account (e.g., India\Domain\user).

  4. Assign the Read-Only Role

    • From the Assigned Role dropdown, choose Read-Only.

  5. Enable Propagation

    • Check the box for Propagate to children to ensure the permission applies to all underlying objects.

  6. Confirm Changes

    • Click OK to apply the changes.

Important Notes

  • Ensure the required user accounts and domain groups are created and synchronized with vCenter before assigning permissions.

  • "Read-Only" role is sufficient for Cloudmon to fetch vCenter data without altering the environment.

  • If integrating multiple vCenters, repeat this process for each instance.