When applying or verifying a password policy across a VMware Cloud Foundation (VCF) environment using VCF Operations Fleet Management, the compliance report for the NSX Manager cluster displays mixed statuses:
Only one NSX Manager node displays a status of Compliant.
The remaining two NSX Manager nodes display a status of Not Eligible.
This behavior is observed under Fleet Management > Password Policy within the VCF Operations user interface.
VMware NSX
This behavior is by design and is a direct result of how the VCF Operations compliance engine interacts with the clustered architecture of NSX Managers.
No action is required.
This is the expected out-of-the-box UI behavior for clustered assets within VCF Operations.
As long as the primary NSX Manager node (or VIP) maintains a status of Compliant, the password policy is successfully active and enforced across the entire underlying NSX Manager cluster fabric.
Targeting the Primary Endpoint: Password policies applied at the VCF Fleet or Instance level are directed toward the active management endpoint (the primary NSX Manager node or the Virtual IP / VIP).
Centralized Evaluation: Fleet Management actively evaluates this primary node to verify policy enforcement. Once validated, it marks this single evaluated node as Compliant.
Internal Synchronization: Nodes within an NSX Manager cluster rely strictly on their internal distributed database synchronization to propagate configuration changes—including local user accounts and password lifecycle details. The policy applied to the primary node automatically synchronizes across the remaining cluster members.