An administrator is troubleshooting a situation where a virtual machine cannot be powered on. The error message indicates insufficient permissions. The VM is in a folder named 'Production' and the administrator has been assigned a custom role with 'Virtual machine > Power On' permission at the folder level. However, the VM is also in a resource pool. What additional permission is most likely missing?
Trap 1: Network > Assign network permission on the network
Powering on a VM does not require network assignment; that permission governs connecting a VM to a port group and is checked when editing network adapters. It is tempting because network permissions appear in VM error messages, but the missing right here relates to the resource pool the VM resides in, not its network.
Trap 2: Datastore > Allocate space permission on the datastore
Allocate space is checked when creating or extending virtual disks, not when powering on an existing VM whose files already reside on the datastore. It is tempting because datastore permissions commonly cause provisioning failures, but the stem's resource pool placement points to a resource-consumption permission instead.
Trap 3: Virtual machine > Configuration permission on the VM
Configuration permission covers editing VM hardware settings, not the power-on operation itself. It is tempting because configuration rights are broad and often bundled with power operations, but the VM's placement in a resource pool means the missing permission concerns resource pool allocation, which the folder-level Power On grant does not supply.
- A
Network > Assign network permission on the network
Why it fails: Powering on a VM does not require network assignment; that permission governs connecting a VM to a port group and is checked when editing network adapters. It is tempting because network permissions appear in VM error messages, but the missing right here relates to the resource pool the VM resides in, not its network.
- B
Resource > Assign virtual machine to resource pool permission on the resource pool
Powering on a VM also requires assigning it to a resource pool, so the custom role must include Resource > Assign virtual machine to resource pool on that pool. Folder-level Power On alone cannot satisfy this separate privilege check.
- C
Datastore > Allocate space permission on the datastore
Why it fails: Allocate space is checked when creating or extending virtual disks, not when powering on an existing VM whose files already reside on the datastore. It is tempting because datastore permissions commonly cause provisioning failures, but the stem's resource pool placement points to a resource-consumption permission instead.
- D
Virtual machine > Configuration permission on the VM
Why it fails: Configuration permission covers editing VM hardware settings, not the power-on operation itself. It is tempting because configuration rights are broad and often bundled with power operations, but the VM's placement in a resource pool means the missing permission concerns resource pool allocation, which the folder-level Power On grant does not supply.