ESXI-67-000003 - The ESXi host must verify the exception users list for Lockdown Mode.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

In vSphere, users can be added to the Exception Users list from the vSphere Web Client. These users do not lose their permissions when the host enters Lockdown Mode.

Before adding service accounts such as a backup agent to the Exception Users list, verify that the list of users who are exempted from losing permissions is legitimate and as needed per the environment. Users who do not require special permissions should not be exempted from Lockdown Mode.

Solution

From the vSphere Client, select the ESXi host and go to Configure >> System >> Security Profile.

Under 'Lockdown Mode', click 'Edit' and remove unnecessary users from the exceptions list.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y22M10_STIG.zip

Item Details

References: CAT|III, CCI|CCI-000366, Rule-ID|SV-239260r674709_rule, STIG-ID|ESXI-67-000003, Vuln-ID|V-239260

Plugin: VMware

Control ID: aed868585996bb720c8cf1346f8af20eb9ec7121d92b0a0683a35b3d8838074d