ESXi : verify-admin-group

Information

The AD group used by vSphere is defined by the 'esxAdminsGroup' attribute, by default this attribute is set to 'ESX Admins'. All members of the 'ESX Admins' group are granted full administrative access to all ESXi hosts in the domain. Monitor AD for the creation of this group and limit membership to highly trusted users and groups.

See Also

https://www.vmware.com/files/xls/hardeningguide-vsphere5-5-ga-released.xlsx

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CSCv6|5.1

Plugin: VMware

Control ID: db81602105e9316253ce58bc1256cf24a2b0c5dd158cb7cfc1fb46782ae942fd