Hyper-V AF_HYPERV permissions and service isolation for VMMS-managed VMs
Hello Microsoft Hyper-V Support,
I am evaluating a security design using an ordinary VMMS-managed Hyper-V VM on Windows 11 Pro and need clarification on the supported AF_HYPERV security and authorization model.
This is a design/documentation question only. No production system, credentials, or customer data are involved.
Could you please clarify the following:
1. Receiver permissions For a dedicated non-administrative host process that only needs to bind/listen/accept on one fixed AF_HYPERV Service ID for one VM, what supported configuration determines its effective permissions?
Can that receiver operate without Hyper-V Administrators membership, service-registration write access, or general VM-management authority?
2. Single-Service-ID isolation Is there a supported host-enforced policy for a VMMS-managed VM that allows exactly one guest-to-host AF_HYPERV Service ID while denying other optional/custom Service IDs before they reach an application handler?
If so, how can the effective policy be queried and verified?
3. Built-in and special endpoints How are built-in or special guest-to-host endpoints related to that policy?
In particular, are PowerShell Direct, KVP, Guest Service Interface, enhanced-session channels, or other built-in endpoints governed by the same policy, separately disableable, or outside that Service-ID model?
4. Peer VM identity For an accepted AF_HYPERV connection, what supported API/fields authoritatively identify the originating VM to the host receiver?
Can a hostile guest influence or substitute that transport-reported identity?
Please distinguish VMMS-managed Hyper-V VMs from HCS-managed containers/VMs. I am not assuming that HCS BindSecurityDescriptor / ConnectSecurityDescriptor settings apply to VMMS unless Microsoft documents that mapping.
Official documentation, supported configuration interfaces, and applicable Windows 11 Pro / Hyper-V version information would be very helpful.
Thank you.