audit-esxi-8.ps1 Script Returns "FAIL" for Active Directory Integration on Joined ESXi Hosts
search cancel

audit-esxi-8.ps1 Script Returns "FAIL" for Active Directory Integration on Joined ESXi Hosts

book

Article ID: 419180

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

When executing the audit-esxi-8.ps1 script from the vSphere Security Configuration and Hardening guidelines, hosts joined to Active Directory (AD) return a false negative result.

  • Joined Host Result:
    [FAIL] <hostname>: Active Directory integration is not configured correctly (<DOMAIN>)

  • Unjoined Host Result:
    [PASS] <hostname>: Active Directory integration is configured correctly ()

 

Resolution

The above result Active Directory integration is not configured correctly is returned  because the host is joined to an Active Directory domain for user authentication. In accordance with the vSphere Security Configuration Guide, joining an ESXi host to an Active Directory domain is no longer recommended. Refer to the VMware vSphere Security Configuration Guide 8.0.3 for the most up-to-date list of active security controls

Additional Information