6.7

Table Of Contents
Lockdown Mode Behavior
In lockdown mode, some services are disabled, and some services are accessible only to certain users.
Lockdown Mode Services for Dierent Users
When the host is running, available services depend on whether lockdown mode is enabled, and on the
type of lockdown mode.
n
In strict and normal lockdown mode, privileged users can access the host through vCenter Server,
either from the vSphere Web Client or by using the vSphere Web Services SDK.
n
Direct Console Interface behavior differs for strict lockdown mode and normal lockdown mode.
n
In strict lockdown mode, the Direct Console User Interface (DCUI) service is disabled.
n
In normal lockdown mode, accounts on the Exception User list can access the DCUI if they have
administrator privileges. In addition, all users who are specified in the DCUI.Access advanced
system setting can access the DCUI.
n
If the ESXi Shell or SSH is enabled and the host is placed in lockdown mode, accounts on the
Exception Users list who have administrator privileges can use these services. For all other users,
ESXi Shell or SSH access is disabled. Starting with vSphere 6.0, ESXi or SSH sessions for users
who do not have administrator privileges are terminated.
All access is logged for both strict and normal lockdown mode.
Table 39. Lockdown Mode Behavior
Service Normal Mode Normal Lockdown Mode Strict Lockdown Mode
vSphere Web Services API All users, based on
permissions
vCenter (vpxuser)
Exception users, based on
permissions
vCloud Director (vslauser, if
available)
vCenter (vpxuser)
Exception users, based on
permissions
vCloud Director (vslauser, if available)
CIM Providers Users with administrator
privileges on the host
vCenter (vpxuser)
Exception users, based on
permissions.
vCloud Director (vslauser, if
available)
vCenter (vpxuser)
Exception users, based on
permissions.
vCloud Director (vslauser, if available)
Direct Console UI (DCUI) Users with administrator
privileges on the host, and
users in the DCUI.Access
advanced option
Users defined in the
DCUI.Access advanced
option
Exception users with
administrator privileges on
the host
DCUI service is stopped
vSphere Security
VMware, Inc. 77