5.10 Ensure DCUI has a trusted users list for lockdown mode

Information

Lockdown mode disables direct host access, requiring admins to manage hosts from vCenter. Set DCUI.Access to a list of highly trusted users who would be able to override lockdown mode and access the DCUI in the event an ESXi host became isolated from vCenter.

NOTE: If you disable lockdown mode using the DCUI, all users with the DCUI.Access privilege will be granted the Administrator role on the host.

Rationale:

The list prevents all admins from becoming locked out and no longer being able to manage the host.

Solution

To set a trusted users list for DCUI, perform the following from the vSphere web client:

Select the host.

Select 'Configure' -> 'System' -> 'Advanced System Settings'.

Type DCUI.Access in the filter.

Click on the attribute to highlight it.

Click edit.

Set the DCUI.Access attribute to a comma-separated list of the users who are allowed to override lockdown mode.

Click 'OK'.

See Also

https://workbench.cisecurity.org/benchmarks/8020

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2, CSCv7|16.6

Plugin: VMware

Control ID: 5f63f57a2df1e86d7839536db0aeac4d4866947822f02d4a73e3c82d02a56c60