6.7

Table Of Contents
5 Click Lockdown Mode and select one of the lockdown mode options.
Option Description
Normal The host can be accessed through vCenter Server. Only users who are on the
Exception Users list and have administrator privileges can log in to the Direct
Console User Interface. If SSH or the ESXi Shell is enabled, access might be
possible.
Strict The host can only be accessed through vCenter Server. If SSH or the ESXi Shell
is enabled, running sessions for accounts in the DCUI.Access advanced option
and for Exception User accounts that have administrator privileges remain
enabled. All other sessions are terminated.
6 Click OK.
Disable Lockdown Mode Using the vSphere Web Client
Disable lockdown mode to allow configuration changes from direct connections to the ESXi host. Leaving
lockdown mode enabled results in a more secure environment.
In vSphere 6.0 you can disable lockdown mode as follows:
From the
vSphere Web Client
Users can disable both normal lockdown mode and strict lockdown mode
from the vSphere Web Client.
From the Direct
Console User Interface
Users who can access the Direct Console User Interface on the ESXi host
can disable normal lockdown mode. In strict lockdown mode, the Direct
Console Interface service is stopped.
Procedure
1 Browse to the host in the vSphere Web Client inventory.
2 Click Configure.
3 Under System, select Security Profile.
4 In the Lockdown Mode panel, click Edit.
5 Click Lockdown Mode and select Disabled to disable lockdown mode.
The system exits lockdown mode, vCenter Server displays an alarm, and an entry is added to the audit
log.
Enable or Disable Normal Lockdown Mode from the Direct Console User
Interface
You can enable and disable normal lockdown mode from the Direct Console User Interface (DCUI). You
can enable and disable strict lockdown mode only from the vSphere Web Client.
When the host is in normal lockdown mode, the following accounts can access the Direct Console User
Interface:
n
Accounts in the Exception Users list who have administrator privileges on the host. The Exception
Users list is meant for service accounts such as a backup agent.
vSphere Security
VMware, Inc. 79