Can't find one last role in vmware roles for azure migrate

GabeCz 6 Reputation points
2025-07-26T03:39:13.8466667+00:00

I understand the following roles are needed Azure Migrate replication to start.

https://learn.microsoft.com/en-us/azure/migrate/migrate-support-matrix-vmware-migration?view=migrate-classic

As i can find all but one, i am unable to locate the 'alias' of "VirtualMachine.Config.ChangeTracking" nor if where to find it.

It would be a great help to see a full list of exact roles to pick in vmware.

If i add "Administrator" role to the migration account migration works. But i am not willing to keep it that way it is highly insecure that way i only did it for testing purposes.

I understand, that the right that is missing is to edit the advanced configuration to add 2 lines to the virtual machine's config, and those are "ctkEnabled" with value TRUE, and "scsi0:0.ctkEnabled" with value of TRUE. (for all drives)

however only if i add advanced configuration, and change settings to the set of roles, it won't do it. i would add every role one by one and take it back if there were 5-10 roles. but there are 100.

a little help?

Azure Migrate
Azure Migrate
A central hub of Azure cloud migration services and tools to discover, assess, and migrate workloads to the cloud.
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Naveena Patlolla 4,805 Reputation points Microsoft External Staff Moderator
    2025-07-27T16:16:59.95+00:00

    Hi GabeCz
    In VMware vSphere Web Client, set up a read-only account to use for vCenter Server:

    From an account that has admin privileges, in vSphere Web Client, on the Home menu, select Administration.

    Under Single Sign-On, select Users and Groups.

    In Users, select New User.

    Enter the account details, and then select OK.

    In the menu under Administration, under Access Control, select Global Permissions.

    Select the user account, and then select Read-only to assign the role to the account. Select OK.

    To be able to start discovery of installed applications and agentless dependency analysis, in the menu under Access Control, select Roles. In the Roles pane, under Roles, select Read-only. Under Privileges, select Guest operations. To propagate the privileges to all objects in the vCenter Server instance, select the Propagate to children checkbox.

    Reference link:
    https://learn.microsoft.com/en-us/azure/migrate/tutorial-discover-vmware?view=migrate-classic#create-an-account-to-access-vcenter-server

    Please let me know if you face any challenge here, I can help you to resolve this issue further

    Provide your valuable Comments.

    Please do not forget to "Accept the answer” and “upvote it” wherever the information provided helps you, this can be beneficial to other community members.it would be greatly appreciated and helpful to others.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.