6.5.1

Table Of Contents
n
Make sure that applications use unique service accounts when connecting to a vCenter Server
system.
Monitor Privileges of vCenter Server Administrator Users
Not all administrator users must have the Administrator role. Instead, create a custom role with the
appropriate set of privileges and assign it to other administrators.
Users with the vCenter Server Administrator role have privileges on all objects in the hierarchy. For
example, by default the Administrator role allows users to interact with files and programs inside a virtual
machine's guest operating system. Assigning that role to too many users can lessen virtual machine data
confidentiality, availability, or integrity. Create a role that gives the administrators the privileges they need,
but remove some of the virtual machine management privileges.
Minimize Access
Do not allow users to log directly in to the vCenter Server host machine. Users who are logged in to the
vCenter Server host machine can cause harm, either intentionally or unintentionally, by altering settings
and modifying processes. Those users also have potential access to vCenter credentials, such as the
SSL certificate. Allow only users who have legitimate tasks to perform to log in to the system and ensure
that login events are audited.
Grant Minimal Privileges to vCenter Server Database Users
The database user requires only certain privileges specific to database access.
Some privileges are required only for installation and upgrade. You can remove these privileges from the
database administrator after vCenter Server is installed or upgraded.
Restrict Datastore Browser Access
Assign the Datastore.Browse datastore privilege only to users or groups who really need those
privileges. Users with the privilege can view, upload, or download files on datastores associated with the
vSphere deployment through the Web browser or the vSphere Web Client.
Restrict Users From Running Commands in a Virtual Machine
By default, a user with the vCenter Server Administrator role can interact with files and programs within a
virtual machine's guest operating system. To reduce the risk of breaching guest confidentiality, availability,
or integrity, create a custom nonguest access role without the Guest Operations privilege. See Restrict
Users From Running Commands Within a Virtual Machine.
Consider Modifying the Password Policy for vpxuser
By default, vCenter Server changes the vpxuser password automatically every 30 days. Ensure that this
setting meets company policy, or configure the vCenter Server password policy. See Set the vCenter
Server Password Policy.
Note Make sure that password aging policy is not too short.
vSphere Security
VMware, Inc. 112