Hi there Experts,
I have recently joined vmware’s platform but my main concern now is the security of the VMs from a Remote Users Group.
From permissions perspective I have blocked the browse datastore, Low level file operations and I have also confirmed that take snapshot option and export to ovf file are disabled for the group of remote users.
Q1) Do I miss any other permission that I should block?
Q2) If a remote user uses his credentials to access the datastores via 3rd party software such
as WinSCP, will be able to eventually browse and copy the datastores??
Q3) Is there any auditing/logging while performing operations to the datastores/vmdks?
(such as for example download operations or export operations)
Q4) Assuming that someone has eventually downloaded the vmdks and
since a windows admin password does not actually protect the access to the files,
is there any native/built-in encryption to the vmdk files?
Thanks,