VCWN-06-000030 - The vCenter Administrator role must be secured and assigned to specific users other than a Windows Administrator.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

By default, vCenter Server grants full administrative rights to the local administrator's account, which can be accessed by domain administrators. Separation of duties dictates that full vCenter Administrative rights should be granted only to those administrators who are required to have it. This privilege should not be granted to any group whose membership is not strictly controlled. Therefore, administrative rights should be removed from the local Windows server to users who are not vCenter administrators.

NOTE: Nessus has not evaluted this check. It is included for informational purposes.

Solution

Under the computer management console for windows view the local administrators group and remove any users or groups that are not vCenter administrators.

See Also

http://iasecontent.disa.mil/stigs/zip/U_VMware_vSphere_6-0_vCenter_Server_for_Windows_V1R3_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, Group-ID|V-63999, Rule-ID|SV-78489r1_rule, STIG-ID|VCWN-06-000030

Plugin: VMware

Control ID: 9772f7ad78b4e4e2e9ad05c30eb876df47a8957ec622c230d1ebc9c552f14bd9