VCSA-80-000305 - The vCenter Server must disable accounts used for Integrated Windows Authentication (IWA).

Information

If not used for their intended purpose, default accounts must be disabled. vCenter ships with several default accounts, two of which are specific to IWA and SASL/Kerberos authentication. If other methods of authentication are used, these accounts are not needed and must be disabled.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From the vSphere Client, go to Administration >> Single Sign On >> Users and Groups >> Users.

Select the "K/M" or "krbtgt/VSPHERE.LOCAL" and click "More" then select "Disable".

Click "Ok" to disable the user account.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_8-0_Y25M01_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-265979r1003616_rule, STIG-ID|VCSA-80-000305, Vuln-ID|V-265979

Plugin: VMware

Control ID: 718924c3b4f9cb98ecf9f354e3e75408c6d470c1a525507100278f9e43591327