I just purchased LEM and I am already stunned that in apparently nobody has a problem with the fact that the CMC via the vShpere client has no password protection. LEM is part of your security umbrella and layered security means that at every corner you should be able to protect accidental or malicious tampering, so locking access would seem something you should expect in the 'base' of every application.
There is a separation of roles, and I should be able to lock any access, but with the LEM that is not possible.
So in my security world that should not even be a customer feature request, but get that done asap.