6.5.1

Table Of Contents
Add Users to the DCUI.Access Advanced Option
The main purpose of the DCUI.Access advanced option is to allow you to exit lockdown mode in case of
catastrophic failure, when you cannot access the host from vCenter Server. You add users to the list by
editing the Advanced Settings for the host from the vSphere Web Client.
Note Users in the DCUI.Access list can change lockdown mode settings regardless of their privileges.
This can impact the security of your host. For service accounts that need direct access to the host,
consider adding users to the Exception Users list instead. Exception user can only perform tasks for
which they have privileges. See Specify Lockdown Mode Exception Users.
Procedure
1 Browse to the host in the vSphere Web Client object navigator.
2 Click Configure.
3 Under System, click Advanced System Settings, and lick Edit.
4 Filter for DCUI.
5 In the DCUI.Access text box, enter the user names, separated by commas.
By default, the root user is included. Consider removing root from the DCUI.Access, list and
specifying a named account for better auditability.
6 Click OK.
Specify Lockdown Mode Exception Users
In vSphere 6.0 and later, you can add users to the Exception Users list from the vSphere Web Client.
These users do not lose their permissions when the host enters lockdown mode. It makes sense to add
service accounts such as a backup agent to the Exception Users list.
Exception users do not lose their privileges when the host enters lockdown mode. Usually these accounts
represent third-party solutions and external applications that need to continue to function in lockdown
mode.
Note The Exception Users list is meant for service accounts that perform very specific tasks, and not for
administrators. Adding administrator users to the Exception Users list defeats the purpose of lockdown
mode.
Exception users are host local users or Active Directory users with privileges defined locally for the ESXi
host. They are not members of an Active Directory group and are not vCenter Server users. These users
are allowed to perform operations on the host based on their privileges. That means, for example, that a
read-only user cannot disable lockdown mode on a host.
Procedure
1 Browse to the host in the vSphere Web Client inventory.
2 Click Configure.
3 Under System, select Security Profile.
vSphere Security
VMware, Inc. 83