6.5.1

Table Of Contents
What to do next
Select the vCenter Server system or the host and assign a permission that pairs the user or group that
should have the new privileges to the newly created role. Remove those users from the Administrator
role.
Prevent a Virtual Machine User or Process From Disconnecting Devices
Users and processes without root or Administrator privileges within virtual machines can connect or
disconnect devices, such as network adapters and CD-ROM drives, and can modify device settings. To
increase virtual machine security, remove these devices. If you do not want to remove a device, you can
change guest operating system settings to prevent virtual machine users or processes from changing the
device status.
Prerequisites
Turn off the virtual machine.
Procedure
1 Log in to a vCenter Server system using the vSphere Web Client and find the virtual machine.
a In the Navigator, select VMs and Templates.
b Find the virtual machine in the hierarchy.
2 Right-click the virtual machine and click Edit Settings.
3 Select VM Options.
4 Click Advanced and click Edit Configuration.
5 Verify that the following values are in the Name and Value columns, or click Add Row to add them.
Name Value
isolation.device.connectable.disable true
isolation.device.edit.disable true
These options override any settings made in the guest operating system's VMware Tools control
panel.
6 Click OK to close the Configuration Parameters dialog box, and click OK again.
Prevent Guest Operating System Processes from Sending Configuration
Messages to the Host
To ensure that the guest operating system does not modify configuration settings, you can prevent these
processes from writing any name-value pairs to the configuration file.
Prerequisites
Turn off the virtual machine.
vSphere Security
VMware, Inc. 139