6.0.3

Table Of Contents
5 Click OK.
6 (Optional) If you made changes to the conguration parameters, restart the virtual machine.
Limiting Exposure of Sensitive Data Copied to the Clipboard
Copy and paste operations are disabled by default for hosts to prevent exposing sensitive data that has been
copied to the clipboard.
When copy and paste is enabled on a virtual machine running VMware Tools, you can copy and paste
between the guest operating system and remote console. As soon as the console window gains focus, non-
privileged users and processes running in the virtual machine can access the clipboard for the virtual
machine console. If a user copies sensitive information to the clipboard before using the console, the user—
perhaps unknowingly—exposes sensitive data to the virtual machine. To prevent this problem, copy and
paste operations for the guest operating system are disabled by default.
It is possible to enable copy and paste operations for virtual machines if necessary.
Restrict Users from Running Commands Within a Virtual Machine
By default, a user with vCenter Server Administrator role can interact with les and programs within a
virtual machine's guest operating system. To reduce the risk of breaching guest condentiality, availability,
or integrity, create a nonguest access role without the Guest Operations privilege.
For security, be as restrictive about allowing access to the virtual data center as you are to the physical data
center. To avoid giving users full administrator access, create a custom role that disables guest access and
apply that role to users who require administrator privileges, but who are not authorized to interact with
les and programs within a guest operating system.
For example, a conguration might include a virtual machine on the infrastructure that has sensitive
information on it. Tasks such as migration with vMotion and Storage vMotion require that the IT role has
access to the virtual machine. In this case, disable some remote operations within a guest OS to ensure that
the IT role cannot access the sensitive information.
Prerequisites
Verify that you have Administrator privileges on the vCenter Server system where you create the role.
Procedure
1 Log in to the vSphere Web Client as a user who has Administrator privileges on the vCenter Server
system where you will create the role.
2 Click Administration and select Roles.
3 Click the Create role action icon and type a name for the role.
For example, type Administrator No Guest Access.
4 Select All Privileges.
5 Deselect All Privileges.Virtual machine.Guest Operations to remove the Guest Operations set of
privileges.
6 Click OK.
What to do next
Select the vCenter Server system or the host and assign a permission that pairs the user or group that should
have the new privileges to the newly created role. Remove those users from the default Administrator role.
vSphere Security
224 VMware, Inc.