1. Home
  2. Security Hardening
  3. DISA STIG VMware vSphere VCenter 6.5 V2R2
  4. VCWN-65-000030 – The vCenter Server for Windows Administrator role must be secured and assigned to specific users other than a Windows Administrator.

VCWN-65-000030 – The vCenter Server for Windows Administrator role must be secured and assigned to specific users other than a Windows Administrator.

Details

By default, vCenter Server grants full administrative rights to the local administrator’s account, which can be accessed by domain administrators. Separation of duties dictates that full vCenter Administrative rights should be granted only to those administrators who are required to have it. This privilege should not be granted to any group whose membership is not strictly controlled. Therefore, administrative rights should be removed from the local Windows server to users who are not vCenter administrators.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Under the computer management console for windows view the local administrators group and remove any users or groups that do not fit the criteria defined in the check content.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system VMware.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles