6.0.3

Table Of Contents
Table 59. Lockdown Mode Behavior (Continued)
Service Normal Mode
Normal Lockdown
Mode Strict Lockdown Mode
ESXi Shell
(if enabled)
Users with administrator
privileges on the host
Users dened in the
DCUI.Access advanced
option
Exception users with
administrator privileges
on the host
Users dened in the DCUI.Access
advanced option
Exception users with administrator
privileges on the host
SSH
(if enabled)
Users with administrator
privileges on the host
Users dened in the
DCUI.Access advanced
option
Exception users with
administrator privileges
on the host
Users dened in the DCUI.Access
advanced option
Exception users with administrator
privileges on the host
Users Logged in to the ESXi Shell When Lockdown Mode Is Enabled
If users are logged in to the ESXi Shell or access the host through SSH before lockdown mode is enabled,
those users who are on the list of Exception Users and who have administrator privileges on the host remain
logged in. Starting with vSphere 6.0, the session is terminated for all other users. This applies to both normal
and strict lockdown mode.
Enable Lockdown Mode Using the vSphere Web Client
Enable lockdown mode to require that all conguration changes go through vCenter Server. vSphere 6.0 and
later supports normal lockdown mode and strict lockdown mode.
To completely disallow all direct access to a host, you can select strict lockdown mode. Strict lockdown
mode makes it impossible to access a host if the vCenter Server is unavailable and SSH and the ESXi Shell
are disabled. See “Lockdown Mode Behavior,” on page 182.
Procedure
1 Browse to the host in the vSphere Web Client inventory.
2 Click the Manage tab and click .
3 Under System, select Security .
4 In the Lockdown Mode panel, click Edit.
5 Click Lockdown Mode and select one of the lockdown mode options.
Option Description
Normal
The host can be accessed through vCenter Server. Only users who are on
the Exception Users list and have administrator privileges can log in to the
Direct Console User Interface. If SSH or the ESXi Shell are enabled, access
might be possible.
Strict
The host can only be accessed through vCenter Server. If SSH or the ESXi
Shell are enabled, running sessions for accounts in the DCUI.Access
advanced option and for Exception User accounts that have administrator
privileges remain enabled. All other sessions are terminated.
6 Click OK.
Chapter 5 Securing ESXi Hosts
VMware, Inc. 183