6.6

Table Of Contents
Patching and Updating the End Point Operations Management Agent
If required, new End Point Operations Management agent bundles are available independent of
vRealize Operations Manager releases.
Patches or updates are not provided for the End Point Operations Management agent. You must install the
latest available version of the agent that includes the latest security xes. Critical security xes will be
communicated as per the VMware security advisory guidance. See the topic on Security Advisories.
Additional Secure Configuration Activities
Verify the server user accounts and delete unnecessary applications from the host servers. Block
unnecessary ports and disable the services running on your host server that are not required.
Verify Server User Account Settings
It is recommended that you verify that no unnecessary user accounts exist for local and domain user
accounts and seings.
Restrict any user account not related to the functioning of the application to those accounts required for
administration, maintenance, and troubleshooting. Restrict remote access from domain user accounts to the
minimum required to maintain the server. Strictly control and audit these accounts.
Delete and Disable Unnecessary Applications
Delete the unnecessary applications from the host servers. Each additional and unnecessary application
increases the risk of exposure because of their unknown or unpatched vulnerabilities.
Disabling Unnecessary Ports and Services
Verify the host server's rewall for the list of open ports that allow trac.
Block all the ports that are not listed as a minimum requirement for vRealize Operations Manager in the
“Conguring Ports and Protocols,” on page 47 section of this document, or are not required. In addition,
audit the services running on your host server and disable those that are not required.
Chapter 3 Secure Configuration of vRealize Operations Manager
VMware, Inc. 37