4.7 Ensure the Exception Users list is properly configured

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Users who are added to the 'Exception Users' list do not lose their permissions when the host enters lockdown mode. Usually you may want to add some service accounts, such as a backup agent, to the Exception Users list.

Rationale:

Users who do not require special permissions should not be exempted from lockdown mode because this increases the risk of unauthorized actions being performed, especially if a user account is compromised.

Solution

To correct the membership of the 'Exception Users' list, perform the following:

From the vSphere web client, select host.

Click on 'Configure' -> 'Settings' -> 'System' -> 'Security Profile'.

Scroll down to 'Lockdown Mode'.

Click 'Edit', then click on 'Exception Users'.

Add or delete users as per your organization's requirements.

See Also

https://workbench.cisecurity.org/files/3511