5.8

Table Of Contents
What to do next
n Evaluate the results and resolve any issues on the noncompliant objects. "Resolve Noncompliant
Compliance Template Results" on page 209.
n If you find results that you want to temporarily make compliant or noncompliant, create an exception.
See "Create Machine Group Compliance Exceptions" on page 211.
Resolve Noncompliant Compliance Template Results
The results for the compliance templates indicate whether the rules were compliant or noncompliant. To
resolve noncompliant results, you might be able to enforce the noncompliant results manually by using
VCM, or you can add an exception for expected noncompliant results.
The following procedures provide a variety of examples that apply to machine group compliance, Active
Directory compliance, and virtual environments compliance.
Procedure
1. "Enforce Compliance Template Results Using Enforceable Compliance" on page 209
You can use enforceable compliance to resolve noncompliant results. Enforceable compliance is a VCM
action that changes settings on physical machines, virtual machines, or virtual objects during or after a
compliance template is run on the machine or object.
2. "Enforce Compliance Template Results by Using VCM Actions" on page 210
You can resolve noncompliant results using VCM actions on the data grids to change settings when
the action is not available for enforceable compliance.
3. "Manually Enforce Compliance Template " on page 211
You can resolve noncompliant results by directly accessing the virtual or physical machine, or by
accessing the object in vCenter Server, to change the noncompliant configuration setting.
4. "Create Machine Group Compliance Exceptions" on page 211
Compliance exceptions are the method you use to temporarily or permanently override specific
template results rather than resolve noncompliant results,
Enforce Compliance Template Results Using Enforceable Compliance
You can use enforceable compliance to resolve noncompliant results. Enforceable compliance is a VCM
action that changes settings on physical machines, virtual machines, or virtual objects during or after a
compliance template is run on the machine or object.
The enforceable compliance action is available for some, but not all, settings. You configure the action in
the rule to allow automatic enforcement during the compliance run or to initiate enforcement after
compliance.
For a list of enforceable data types, see one of the following lists:
n Enforceable Compliance Windows Data Types and Properties
n Enforceable Compliance UNIX Data Types and Properties
n Enforceable Compliance Virtual Environment Data Types and Properties
If the rule is configured for automatic enforcement, VCM changes the noncompliant setting to the
compliant value on the affected machine or object after the compliance assessment runs. If the rule is not
configured for automatic enforcement, you select a noncompliant rule and enforce it. VCM then changes
the value on the affected machine or object to the required compliant value.
Running and Enforcing Compliance
VMware, Inc.
209