Specifications

www.vmware.com
106
VMware GSX Server Administration Guide
Securing Virtual Machines and the Host
This section describes how you can set permissions and implement security features
for your virtual machines and the server host.
The VMware Knowledge Base has an article about best practices you can use to
improve security for the GSX Server host and virtual machines. For information, see
www.vmware.com/support/kb/enduser/std_adp.php?&p_faqid=1042.
Understanding Permissions and Virtual Machines
Access to a virtual machine is based on the permissions you, as a user, are granted to
the virtual machine's configuration file (.vmx). Different permissions let you access
virtual machines in different ways. These ways include:
Browsing virtual machines.
Interacting with virtual machines.
Configuring virtual machines.
Administering virtual machines and the host.
If the virtual machine is on a Windows host, permissions on more virtual machine files
may be needed, depending upon the user account the virtual machine uses while
running. For information, see Authenticating Users and Running Virtual Machines on a
GSX Server for Windows Host on page 108.
Browsing a Virtual Machine
Browsing a virtual machine lets you connect to it with a console, but you can see only
the virtual machine’s power state. The virtual machine display is blank, even if the
virtual machine is running. You cannot interact with the virtual machine at all.
To browse a virtual machine, you need Read permission for the virtual machine’s
configuration file on a Windows host, or read (r) permission on a Linux host.
Interacting with a Virtual Machine
Interacting with a virtual machine lets you change its power state (power it on or off,
suspend or resume it) and connect or disconnect removable devices. You cannot
change the virtual machine’s configuration. Among other restrictions, this means you
cannot add or remove virtual hardware.
Your user name appears in the VMware Management Interface and in the Connected
Users dialog box, which you access in the VMware Virtual Machine Console by
choosing VM > Connected Users.