6.5.1

Table Of Contents
Limiting Exposure of Sensitive Data Copied to the Clipboard
Copy and paste operations are disabled by default for hosts to prevent exposing sensitive data that has
been copied to the clipboard.
When copy and paste is enabled on a virtual machine running VMware Tools, you can copy and paste
between the guest operating system and remote console. When the console window gains focus,
processes running in the virtual machine and non-privileged users can access the virtual machine
console clipboard. If a user copies sensitive information to the clipboard before using the console, the use
might expose sensitive data to the virtual machine. To prevent this problem, copy and paste operations
for the guest operating system are disabled by default.
It is possible to enable copy and paste operations for virtual machines if necessary.
Restrict Users From Running Commands Within a Virtual Machine
By default, a user who has the vCenter Server Administrator role can interact with files and applications
within a virtual machine's guest operating system. To reduce the risk of breaching guest confidentiality,
availability, or integrity, create a nonguest access role without the Guest Operations privilege. Assign
that role to administrators who do not need virtual machine file access.
For security, be as restrictive about allowing access to the virtual data center as you are to the physical
data center. Apply a custom role that disables guest access to users who require administrator privileges,
but who are not authorized to interact with guest operating system files and applications.
For example, a configuration might include a virtual machine on the infrastructure that has sensitive
information on it.
If tasks such as migration with vMotion require that data center administrators can access the virtual
machine, disable some remote guest OS operations to ensure that those administrators cannot access
sensitive information.
Prerequisites
Verify that you have Administrator privileges on the vCenter Server system where you create the role.
Procedure
1 Log in to the vSphere Web Client as a user who has Administrator privileges on the vCenter Server
system where you will create the role.
2 Click Administration and select Roles.
3 Click the Create role action icon and type a name for the role.
For example, type Administrator No Guest Access.
4 Select All Privileges.
5 Deselect All Privileges.Virtual machine.Guest Operations to remove the Guest Operations set of
privileges.
6 Click OK.
vSphere Security
VMware, Inc. 138