Information
Users who are added to the "Exception Users" list do not lose their permissions when the
  host enters lockdown mode. Usually you may want to add some service accounts, such as a
  backup agent, to the Exception Users list.
*Rationale*
Users who do not require special permissions should not be exempted from
lockdown mode because this increases the risk of unauthorized actions being performed, especially if
a user account is compromised.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To correct the membership of the "Exception Users" list, perform the following:
1. From the vSphere web client, select host.
2. Click on "Configure" -> "Settings" -> "System" -> "Security Profile".
3. Scroll down to "Lockdown Mode".
4. Click "Edit", then click on "Exception Users".
5. Add or delete users as per your organization's requirements.