6.0.3

Table Of Contents
Specifying Accounts with Access Privileges in Lockdown Mode
You can specify service accounts that can access the ESXi host directly by adding them to the Exception
Users list. You can specify a single user who can access the ESXi host in case of catastrophic vCenter Server
failure.
What dierent accounts can do by default when lockdown mode is enabled, and how you can change the
default behavior, depends on the version of the vSphere environment.
n
In versions of vSphere earlier than vSphere 5.1, only the root user can log into the Direct Console User
Interface on an ESXi host that is in lockdown mode.
n
In vSphere 5.1 and later, you can add a user to the DCUI.Access advanced system seing for each host.
The option is meant for catastrophic failure of vCenter Server, and the password for the user with this
access is usually locked into a safe. A user in the DCUI.Access list does not need to have full
administrative privileges on the host.
n
In vSphere 6.0 and later, the DCUI.Access advanced system seing is still supported. In addition,
vSphere 6.0 and later supports an Exception User list, which is for service accounts that have to log in to
the host directly. Accounts with administrator privileges that are on the Exception Users list can log in
to the ESXi Shell. In addition, those user can log in to a host's DCUI in normal lockdown mode and can
exit lockdown mode.
You specify Exception Users from the vSphere Web Client.
N Exception users are host local users or Active Directory users with privileges dened locally for
the ESXihost. Users that are members of an Active Directory group lose their permissions when the host
is in lockdown mode.
Add Users to the DCUI.Access Advanced Option
The main purpose of the DCUI.Access advanced option is to allow you to exit lockdown mode in case of
catastrophic failure, when you cannot access the host from vCenter Server. You add users to the list by
editing the Advanced Seings for the host from the vSphere Web Client.
N Users in the DCUI.Access list can change lockdown mode seings regardless of their privileges. This
can impact the security of your host. For service accounts that need direct access to the host, consider adding
users to the Exception Users list instead. Exception user can only perform tasks for which they have
privileges. See “Specify Lockdown Mode Exception Users,” on page 186.
Procedure
1 Browse to the host in the vSphere Web Client object navigator.
2 Click the Manage tab and select .
3 Click Advanced System  and select DCUI.Access.
4 Click Edit and enter the user names, separated by commas.
By default, the root user is included. Consider removing root from the DCUI.Access, list and specifying
a named account for beer auditability.
5 Click OK.
Chapter 5 Securing ESXi Hosts
VMware, Inc. 185