6.7

Table Of Contents
Table 39. Lockdown Mode Behavior (Continued)
Service Normal Mode Normal Lockdown Mode Strict Lockdown Mode
ESXi Shell
(if enabled)
Users with administrator
privileges on the host
Users defined in the
DCUI.Access advanced
option
Exception users with
administrator privileges on
the host
Users defined in the DCUI.Access
advanced option
Exception users with administrator
privileges on the host
SSH
(if enabled)
Users with administrator
privileges on the host
Users defined in the
DCUI.Access advanced
option
Exception users with
administrator privileges on
the host
Users defined in the DCUI.Access
advanced option
Exception users with administrator
privileges on the host
Users Logged in to the ESXi Shell When Lockdown Mode Is Enabled
Users might log in to the ESXi Shell or access the host through SSH before lockdown mode is enabled. In
that case, users who are on the list of Exception Users and who have administrator privileges on the host
remain logged in. Starting with vSphere 6.0, the session is terminated for all other users. Termination
applies to both normal and strict lockdown mode.
Enable Lockdown Mode Using the vSphere Web Client
Enable lockdown mode to require that all configuration changes go through vCenter Server. vSphere 6.0
and later supports normal lockdown mode and strict lockdown mode.
If you want to disallow all direct access to a host completely, you can select strict lockdown mode. Strict
lockdown mode makes it impossible to access a host if the vCenter Server is unavailable and SSH and
the ESXi Shell are disabled. See Lockdown Mode Behavior.
Procedure
1 Browse to the host in the vSphere Web Client inventory.
2 Click Configure.
3 Under System, select Security Profile.
4 In the Lockdown Mode panel, click Edit.
vSphere Security
VMware, Inc. 78