6.0.3

Table Of Contents
Table 24. Groups in the vsphere.local Domain (Continued)
Privilege Description
SystemConguration.Administrators Members of the SystemConguration.Administrators group can view and
manage the system conguration in the vSphere Web Client. These users can
view, start and restart services, troubleshoot services, see the available nodes and
manage those nodes.
DCClients This group is used internally to allow the management node access to data in
VMware Directory Service.
N Do not modify this group. Any changes might compromise your
certicate infrastructure.
ComponentManager.Administrators Members of the ComponentManager.Administrators group can invoke
component manager APIs that register or unregister services, that is, modify
services. Membership in this group is not necessary for read access on the
services.
LicenseService.Administrators Members of LicenseService.Administrators have full write access to all licensing
related data and can add, remove, assign, and unassign serial keys for all
product assets registered in licensing service.
Administrators Administrators of the VMware Directory Service (vmdir). Members of this group
can perform vCenter Single Sign-On administration tasks. Adding members to
this group is not usually recommended.
vCenter Server Password Requirements and Lockout Behavior
To manage your environment, you must be aware of the vCenter Single Sign-On password policy, of
vCenter Server passwords, and of lockout behavior.
vCenter Single Sign-On Administrator Password
The password for administrator@vsphere.local must meet the following requirements:
n
At least 8 characters
n
At least one lowercase character
n
At least one numeric character
n
At least one special character
The password for administrator@vsphere.local cannot be more than 20 characters long. Only visible ASCII
characters are allowed. That means, for example, that you cannot use the space character.
vCenter Server Passwords
In vCenter Server, password requirements are dictated by vCenter Single Sign-On or by the congured
identity source, which can be Active Directory, OpenLDAP, or the local operating system for the vCenter
Single Sign-On server (not recommended).
Lockout Behavior
Users are locked out after a preset number of consecutive failed aempts. By default, users are locked out
after ve consecutive failed aempt in three minutes and a locked account is unlocked automatically after
ve minutes. You can change these defaults using the lockout policy. See “Edit the vCenter Single Sign-On
Lockout Policy,” on page 52.
Starting with vSphere 6.0, the system domain administrator, administrator@vsphere.local by default, is not
aected by the lockout policy.
Any user can change their password by using the dir-cli password change command. If a user forgets the
password, the administrator can reset the password by using the dir-cli password reset command.
vSphere Security
28 VMware, Inc.