Users and processes without root or administrator privileges within virtual machines can connect or disconnect devices, such as network adapters and CD-ROM drives, and can modify device settings. To increase virtual machine security, remove these devices.

You can prevent virtual machine users in the guest OS, and processes running in the guest OS, from making any changes to the devices by changing the virtual machine advanced settings.

Prerequisites

Turn off the virtual machine.

Procedure

  1. Browse to the virtual machine in the vSphere Client inventory.
  2. Right-click the virtual machine and click Edit Settings.
  3. Select VM Options.
  4. Click Advanced and click Edit Configuration.
  5. Verify that the following values are in the Name and Value columns, or add them.
    Name Value
    isolation.device.connectable.disable true
    isolation.device.edit.disable true
    These settings do not affect a vSphere administrator's ability to connect or disconnect the devices attached to the virtual machine.
  6. Click OK to close the Configuration Parameters dialog box, and click OK again.