1.0

Table Of Contents
www.vmware.com
220
VMware ACE Administrator’s Manual
Taking Advantage of Policies
With policies, you can specify what controls your end users see when they launch
VMware ACE, how long they may run a particular virtual machine, what parts of your
organizations network they are allowed to use from the virtual machine and many
other capabilities of the VMware ACE application and the virtual machine it runs for
the end user.
You set policies with the policy editor. You can run the policy editor immediately after
you create a new virtual machine or launch it later from the project or virtual machine
summary display in VMware ACE Manager. For details on how to use the policy editor,
see Setting Policies for a Project on page 71.
You can change some or all of the policies for a VMware ACE virtual machine at any
time by editing the policies, then creating and distributing a new package that
contains only the policies.
For some policies, you can effectively make changes at any time, without deploying a
new package to your end users. The following examples describe some of the things
you can do:
Authentication: If you authenticate users based on users and groups in your
Active Directory service, you can change the access list for a virtual machine at
any time. VMware ACE Manager stores the changes in your Active Directory
service, and all installations of that virtual machine will respect the new access
list the next time end users launch them. For more information, see Encryption
and Authentication Policies on page 222.
Network quarantine: With most of the network quarantine options, you can
change network access at any time. Use dynamic quarantine, conditional
quarantine or custom quarantine and specify that the access list governing
network access is stored on a Web server or in your Active Directory service. You
can then modify the access list at any time, using VMware ACE Manager, and the
affected virtual machines will respect the new network quarantine conditions
the next time they connect to the network. For more information, see Network
Quarantine Policies on page 230.
The policies you set for a project are stored in a policy (.vmpl) file with a filename
corresponding to that of the virtual machine’s configuration (.vmx) file. The policy file
is stored in the directory that stores the project files. Policies can be changed by
anyone running VMware ACE Manager who has permission to modify the file.
Note: If you store policies on your Active Directory server, you must be sure end
users’ host computers have been added to the domain where the policies are stored