6.0.3

Table Of Contents
Privileged users can disable lockdown mode from the vSphere Web Client. They can disable normal
lockdown mode from the Direct Console Interface, but they cannot disable strict lockdown mode from the
Direct Console Interface.
N If you enable or disable lockdown mode using the Direct Console User Interface, permissions for
users and groups on the host are discarded. To preserve these permissions, you can enable and disable
lockdown mode using the vSphere Web Client.
Lockdown Mode Behavior
In lockdown mode, some services are disabled, and some services are accessible only to certain users.
Lockdown Mode Services for Different Users
When the host is running, available services depend on whether lockdown mode is enabled, and on the type
of lockdown mode.
n
In strict and normal lockdown mode, privileged users can access the host through vCenter Server,
either from the vSphere Web Client or by using the vSphere Web Services SDK.
n
Direct Console Interface behavior diers for strict lockdown mode and normal lockdown mode.
n
In strict lockdown mode, the Direct Console User Interface (DCUI) service is disabled.
n
In normal lockdown mode, accounts on the Exception User list who have administrator privileges
and users who are specied in the DCUI.Access advanced system seing can access the Direct
Console Interface.
n
If the ESXi Shell or SSH are enabled and the host is placed in strict or normal lockdown mode, accounts
on the Exception Users list who have administrator privileges can use these services. For all other users,
ESXi Shell or SSH access is disabled. Starting with vSphere 6.0, ESXi or SSH sessions for users who do
not have administrator privileges are terminated.
All access is logged for both strict and normal lockdown mode.
Table 59. Lockdown Mode Behavior
Service Normal Mode
Normal Lockdown
Mode Strict Lockdown Mode
vSphere Web Services API All users, based on
permissions
vCenter (vpxuser)
Exception users, based
on permissions
vCloud Director
(vslauser, if available)
vCenter (vpxuser)
Exception users, based on
permissions
vCloud Director (vslauser, if
available)
CIM Providers Users with administrator
privileges on the host
vCenter (vpxuser)
Exception users, based
on permissions.
vCloud Director
(vslauser, if available)
vCenter (vpxuser)
Exception, based on permissions.
vCloud Director (vslauser, if
available)
Direct Console UI (DCUI) Users with administrator
privileges on the host ,
and users in the
DCUI.Access advanced
option
Users dened in the
DCUI.Access advanced
option
Exception users with
administrator privileges
on the host
DCUI service is stopped
vSphere Security
182 VMware, Inc.