vCenter: vcenter-8.administration-sso-password-reuse

Information

Configure the password history setting to restrict the reuse of passwords on the vCenter Server. Password complexity rules may lead users to reuse old passwords. Configuring the password history setting on the vCenter Server can help prevent this.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Get-SsoPasswordPolicy | Set-SsoPasswordPolicy -ProhibitedPreviousPasswordsCount 5

See Also

https://github.com/vmware/vcf-security-and-compliance-guidelines/raw/refs/heads/main/security-configuration-hardening-guide/vsphere/8.0/

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(b), CCI|CCI-004061

Plugin: VMware

Control ID: 106d4d7363958ed59697cd8b88d0b7a52696633645314705b97ebcfd4ff6cc64