vCenter : check-privilege-reassignment

Information

During a restart of vCenter Server, if the user or user group that is assigned Administrator Role on the root folder could not be verified as a valid user/group during the restart, the user/group's permission as Administrator will be removed. In its place, vCenter Server grants the Administrator role to the local Windows administrators group, to act as a new vCenter Server administrator. Since it is not recommended to grant vCenter Server Administrator rights to Windows Administrators, this results in a situation that should be rectified by re-establishing a legitimate administrator account.

See Also

https://www.vmware.com/files/xls/hardeningguide-vsphere5-5-ga-released.xlsx