6.0.3

Table Of Contents
Disable Lockdown Mode Using the vSphere Web Client
Disable lockdown mode to allow conguration changes from direct connections to the ESXi host. Leaving
lockdown mode enabled results in a more secure environment.
In vSphere 6.0 you can disable lockdown mode as follows:
From the
vSphere Web Client
Users can disable both normal lockdown mode and strict lockdown mode
from the vSphere Web Client.
From the Direct Console
User Interface
Users who can access the Direct Console User Interface on the ESXi host can
disable normal lockdown mode. In strict lockdown mode, the Direct Console
Interface service is stopped.
Procedure
1 Browse to the host in the vSphere Web Client inventory.
2 Click the Manage tab and click .
3 Under System, select Security .
4 In the Lockdown Mode panel, click Edit.
5 Click Lockdown Mode and select None to disable lockdown mode.
The system exits lockdown mode, vCenter Server displays an alarm, and an entry is added to the audit log.
Enable or Disable Normal Lockdown Mode from the Direct Console User Interface
You can enable and disable normal lockdown mode from the Direct Console User Interface (DCUI). You can
enable and disable strict lockdown mode only from the vSphere Web Client.
When the host is in normal lockdown mode, the following accounts can access the Direct Console User
Interface:
n
Accounts in the Exception Users list who have administrator privileges on the host. The Exception
Users list is meant for service accounts such as a backup agent.
n
Users dened in the DCUI.Access advanced option for the host. This option can be used to enable
access in case of catastrophic failure.
For ESXi 6.0 and later, user permissions are preserved when you enable lockdown mode, and are restored
when you disable lockdown mode from the Direct Console Interface.
N If you upgrade a host that is in lockdown mode to ESXi version 6.0 without exiting lockdown mode,
and if you exit lockdown mode after the upgrade, all the permissions dened before the host entered
lockdown mode are lost. The system assigns the administrator role to all users who are found in the
DCUI.Access advanced option to guarantee that the host remains accessible.
To retain permissions, disable lockdown mode for the host from the vSphere Web Client before the upgrade.
Procedure
1 At the Direct Console User Interface of the host, press F2 and log in.
2 Scroll to the  Lockdown Mode seing and press Enter to toggle the current seing.
3 Press Esc until you return to the main menu of the Direct Console User Interface.
vSphere Security
184 VMware, Inc.