troubleshooting Question

Why can all Domain Users seemingly launch the VMM 2012 R2 console and modify my VMs?

Avatar of amendala
amendala asked on
Hyper-VVirtualizationWindows Server 2012
8 Comments1 Solution371 ViewsLast Modified:
Greetings -

Folks, I've run into something that is very concerning to me in my new VMM 2012 R2 environment.  I've found that seemingly any domain user in my domain can launch the VMM 2012 R2 console (if installed on their machine of course), and they can not only connect to the VMM server but also modify properties of my VMs, start/stop them, etc.  They can't connect to the console session but at any rate, this is highly concerning from an RBAC perspective.

The only built-in RBAC group in VMM that I can see is "Administrators".  The membership of this group contains all the defaults (i.e. the VMM server computer account, service account, default action account, Domain Admins, etc.)  It does *not* however contain any groups that would include Domain Users or any broad global/universal groups.

So why anyone can launch the console and play with my VMs, I have no idea.  Where else should I be looking for access rights?  Aside from my server administrators, I don't want anyone to be able to launch the console and connect, let alone make any setting changes or even see any VMs for that matter.

Ideas?  What am I missing about VMM 2012 R2 versus the old VMM 2008 R2 world where this was seemingly simpler or at least more secure/functional?

Thanks in advance.

Edit - Additional Information:

My VMM environment is extremely simple at this point as it is in the early stages of configuration.  Only a few hosts, about 20 VMs, a single private cloud, single domain, nothing extravagant.  It is VMM 2012 R2 (Update Rollup 4) running on a fully patched Server 2012 R2 box.
ASKER CERTIFIED SOLUTION
amendala

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 8 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 8 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros