VMware Cloud Community
sumitgad
Contributor
Contributor

Restrict access to Vmware Tools

Hi, I am using VMware ESX 3.5 and runnig around 50 Virtual Machines. While logging onto the Virtual Machine through Remote Console, I found that the Vmware tools icon in the system tray and the same icon is is also visible to all the users who takes the RDP of these Virtual Server. In that case any user can open the Vmware tools console and from the device tab anyone can disconnect the Network adaptor attached to the vm. So in order to restrict the access to the vmware tools icon I Edit the registry key "HKEY_CURRENT_USER\Software\VMware, Inc.\VMware Tools" and set ShowTray equal to 0 . With this setting the icon is no more visible in the system tray but it is still accessible through Control panel -> Vmware Tools.

Is there a way to restrict the complete access to the Vmware tools installed on a VM server.?

0 Kudos
6 Replies
RParker
Immortal
Immortal

This hasn't been a problem before.. What is the problem with the tools? Users can't do anything to them or gain access to an ESX host, so what's the problem with seeing the tools or having access to them?

They aren't any different than any other normal service in Windows. If you give them admin rights to the VM, they can change it. If you restrict their access to something like a power user, then they can't, that's probably your best option.

0 Kudos
sumitgad
Contributor
Contributor

There is no problem with the tools. The issue is that, any normal windows user with the basic rights woh just has the login rights on to server can open the Vmware tools console and can disconnect the device like network card or IDE controller connected to the Virtual machine.

See the attached screenshot.

0 Kudos
Texiwill
Leadership
Leadership

Hello,

Moved to Security and Compliance forum

I would open this up as a bug with your VMware Support SPecialist. In the meantime you will need to disable the showing of the tray and set the permissions on the VMware Tools applications to deny access if you are not an administrator. Or use an application firewall, etc.


Best regards,

Edward L. Haletky

VMware Communities User Moderator

====

Author of the book 'VMWare ESX Server in the Enterprise: Planning and Securing Virtualization Servers', Copyright 2008 Pearson Education.

CIO Virtualization Blog: http://www.cio.com/blog/index/topic/168354

As well as the Virtualization Wiki at http://www.astroarch.com/wiki/index.php/Virtualization

--
Edward L. Haletky
vExpert XIV: 2009-2023,
VMTN Community Moderator
vSphere Upgrade Saga: https://www.astroarch.com/blogs
GitHub Repo: https://github.com/Texiwill
0 Kudos
sumitgad
Contributor
Contributor

Hi,

I have already disable the showing of the tray icon by seting up the registry value but not sure about how to set the permission on the Vmware tools application to restrict user access.Do you have any idea about how we can do this.

Also do inform me if you get any reply from Vmware regarding this issue.

Regards,

Sumit Gupta

Vmware Certified Professional

0 Kudos
Texiwill
Leadership
Leadership

Hello,

You should open a support case. I can not do that on your behalf.

CHange the permissions of the application within the guest OS. Deny non-administrators from starting the toolbox and anything else vmware related. There is nothing you can do from the virtual hardware, it is a guest OS issue regarding permissions.


Best regards,

Edward L. Haletky

VMware Communities User Moderator

====

Author of the book 'VMWare ESX Server in the Enterprise: Planning and Securing Virtualization Servers', Copyright 2008 Pearson Education.

CIO Virtualization Blog: http://www.cio.com/blog/index/topic/168354

As well as the Virtualization Wiki at http://www.astroarch.com/wiki/index.php/Virtualization

--
Edward L. Haletky
vExpert XIV: 2009-2023,
VMTN Community Moderator
vSphere Upgrade Saga: https://www.astroarch.com/blogs
GitHub Repo: https://github.com/Texiwill
0 Kudos
wila
Immortal
Immortal

Hi,

You didn't say which OS you are using (well OK windows) so here is a possible workaround with general notes (should work on any windows machine, but detaisl might be slightly different)

If you open services under Control Panel -> administrative tools and browse to the "VMware Tools Service", select properties and look for tab page "Log On"

You'll see the user the service runs under and you can change that down there.

However, there's also an option "interact with desktop" and unchecking that will normally disable all UI interactions for the service.

Haven't tried it here, but it should work.

As always, make backups before changing this.

--

Wil

Message was edited by: wila, PS: You might have to restart the service (or the machine) in order to see the changes take effect.

| Author of Vimalin. The virtual machine Backup app for VMware Fusion, VMware Workstation and Player |
| More info at vimalin.com | Twitter @wilva
0 Kudos