Information
The vCenter Server must separate authentication and authorization for administrators. Combining authentication and authorization, as done in services like Active Directory, risks infrastructure breaches if compromised. Hence, vCenter Server should segregate these for administrators. Consider local SSO groups for authorization to better manage risk where feasible.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
N/A (No public API available)