vCenter permission auditing and anomaly detection tool for compliance-driven environments.
Analyzes all vCenter permission assignments to answer:
- Who has access to what?
- How far does propagation go?
- Are there anomalies (orphaned, over-privileged, sprawl)?
Produces audit-ready reports with remediation commands.
- Banks and financial institutions (BDDK/SPK audits)
- Enterprise VMware environments
- Security and compliance teams
| Feature | Description |
|---|---|
| Permission Inventory | Collects and normalizes all vCenter permissions |
| 6 Anomaly Types | OverPrivileged, Orphaned, DirectUser, Propagation, ServiceAccount, CrossDC |
| Role Analysis | Custom roles, unused roles, risk ranking by privilege count |
| Permission Sprawl | Top principals, over-permissioned objects, root assignments |
| HTML Report | Dark/light theme, SVG charts, filterable tables, remediation roadmap |
| AD Integration | Optional Active Directory validation (-CheckAD) |
| Redaction | Mask principal names for external sharing (-RedactPrincipals) |
| Multi-format | HTML, JSON, CSV export |
# WhatIf mode (no vCenter required — uses mock data)
.\vPermission-Audit.ps1 -WhatIf
# Real vCenter connection
.\vPermission-Audit.ps1 -VCenterServer vcsa.lab.local -Credential (Get-Credential)
# Full audit with AD check and all export formats
.\vPermission-Audit.ps1 -VCenterServer vcsa.lab.local -CheckAD -ReportFormat All
# Redacted report for external auditors
.\vPermission-Audit.ps1 -VCenterServer vcsa.lab.local -RedactPrincipals -ReportFormat HTML- PowerShell 7.2+
- VMware.PowerCLI module (for real vCenter connections)
- ActiveDirectory module (optional, for -CheckAD)
| Parameter | Type | Default | Description |
|---|---|---|---|
-VCenterServer |
string | config.json | vCenter FQDN or IP |
-Credential |
PSCredential | prompt | vCenter credential |
-ConfigFile |
string | ./config.json | Configuration file path |
-OutputPath |
string | ./output | Report output directory |
-ReportFormat |
string | HTML | HTML, JSON, CSV, or All |
-CheckAD |
switch | false | Enable AD principal validation |
-ADCredential |
PSCredential | implicit | AD query credential |
-RedactPrincipals |
switch | false | Mask names in report |
-WhatIf |
switch | false | Mock data mode |
| Key | Default | Description |
|---|---|---|
overPrivilegedThreshold |
50 | Privilege count to flag custom roles |
serviceAccountPatterns |
svc-, sa-, *_svc | Service account name patterns |
adminRoleNames |
Admin, Administrator | Role names considered admin-level |
sprawlThreshold |
10 | Permission count to flag principal sprawl |
objectPermissionWarnCount |
5 | Permission count to flag object sprawl |
excludePrincipals |
[] | Principals to exclude from analysis |
| Type | Severity | Detection |
|---|---|---|
| OverPrivileged | CRITICAL/HIGH | Admin role on non-root objects |
| OrphanedPermission | MEDIUM | SID-format or deleted AD principals |
| DirectUserPermission | LOW | Individual user instead of group |
| PropagationAnomaly | HIGH | Admin propagating from root/DC by user |
| ServiceAccountOverPrivilege | HIGH | Service accounts with Admin role |
| CrossDatacenterPermission | MEDIUM | Same principal across 2+ datacenters |
- Overview — Score ring, stat cards, severity donut chart, category bars
- Anomalies — Filterable table by severity
- Permission Matrix — Principal-based cards with role:object mappings
- Role Inventory — All roles with privilege counts and risk levels
- Sprawl Analysis — SVG bar chart of top 10 principals
- Remediation — Prioritized actions with
Remove-VIPermissioncommands
This tool produces sensitive output (who has access to what). Keep reports secure.
Use -RedactPrincipals for external sharing — it generates a separate key file.
MIT