4.4 Use Active Directory for local user authentication - Enabled = 'true'

Information

http://pubs.vmware.com/vsphere-51/topic/com.vmware.vsphere.security.doc/GUID-A61A8FA4-A4AF-475C-860E-3FD8947F0D0B.html

Solution

From the vSphere Web Client-
1. Select the host and go to 'Manage' -> 'Authentication Services' and click the 'Join Domain' button.
2. Provide the domain name along with the user credentials for an AD user that has the
rights to join computers to the domain.To implement the recommended configuration state, run the following PowerCLI
command-# Join the ESXI Host to the Domain
Get-VMHost HOST1 | Get-VMHostAuthentication | Set-VMHostAuthentication -Domain
domain.local -User Administrator -Password Passw0rd -JoinDomainNotes-1. Host Profiles can be used to automate adding hosts to an AD domain.
2. Consider using the vSphere Authentication proxy to avoid transmitting AD
credentials over the network.
3. If the AD group 'ESX Admins' (default) is created all users and groups that are
assigned as members to this group will have full administrative access to all ESXi
hosts the domain.

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2

Plugin: VMware

Control ID: e5ec778e0fce32f49aea7ac4ca96062e51a2140be24bc25a441dea8f0e0da02c