Best Practices for Managing and Disabling the administrator@vsphere.local Account
search cancel

Best Practices for Managing and Disabling the administrator@vsphere.local Account

book

Article ID: 446352

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

Organizations performing security audits may seek to implement a "least privilege" model by disabling default accounts or replacing them with named accounts. This often results in queries regarding:

  • The impact of disabling administrator@vsphere.local.
  • Functional dependencies on the default SSO account.
  • The ability of vCenter to function with a named replacement account (e.g., user@vsphere.local).

Environment

VMware vCenter Server

Cause

This is a guidance request for audit compliance and security hardening.

Resolution

Broadcom recommends retaining the administrator@vsphere.local account due to critical system dependencies. Disabling this account may lead to failures in the following areas:

  • System Upgrades: The default account is required for patching and major version upgrades.
  • Emergency Recovery: Serves as the primary "break-glass" access if external identity sources (AD/LDAP) fails in VMC environments.
  • Internal Tools: Tools like "VDT" and "lsdoctor" rely on this account for authentication.
  • Enhanced Linked Mode (ELM): Often used for inter-vCenter authentication.

Recommended Alternative for Audit Compliance: Instead of disabling the default account, create a named SSO user with equivalent privileges:

  1. Log in to the vSphere Client as administrator@vsphere.local.
  2. Navigate to Administration > Single Sign-On > Users and Groups.
  3. Create the new user (e.g., audit_admin@vsphere.local).
  4. Add the user to the Administrators group.
  5. If appliance management (VAMI) is required, add the user to the SystemConfiguration.BashShellAdministrators group.

Additional Information

 

For more information on managing SSO users, Contact Support by creating Broadcom support case.