vsphere.local system accounts and groups cleanup guidance for vCenter Server
search cancel

vsphere.local system accounts and groups cleanup guidance for vCenter Server

book

Article ID: 450189

calendar_today

Updated On:

Products

VMware vCenter Server VMware Cloud Foundation

Issue/Introduction

  • Security audits in VMware Cloud Foundation (VCF) or standard vCenter Server environments may flag unused or "empty" groups and accounts in the vsphere.local domain. These identities are created automatically during bring-up, installation, or upgrades.
  • Auditor flags "weak maintenance" on local accounts/groups.
  • Numerous waiter-xxxx or krbtgt accounts appear in the SSO domain.
  • Groups such as ActAsUsers, CAAdmins, DCAdmins, and DCClients appear empty in the vSphere UI.

Environment

VMware vCenter Server

VMware Cloud Foundation

Cause

  • These identities are internal system service principals required for service isolation, Kerberos authentication, and certificate management. Many groups contain "Solution Users" that are hidden from the standard vSphere Client UI.

Resolution

  • Do not delete or modify these system-generated groups and accounts. Removal causes environment instability, authentication failures, and blocks future lifecycle management (LCM) tasks.
    1. Identify Internal Systesm Accounts: Run the vCenter command to list system service accounts: # /usr/lib/vmware-vmafd/bin/dir-cli svcaccount list
    2. Verify Internal Group Membership: View hidden solution users within the groups of interest: # /usr/lib/vmware-vmafd/bin/dir-cli group list --name CAAdmins
    3. Refer to the following KBs and documentation for more information:
      • waiter-xxxx: Used by Auto Deploy. Disable only if Auto Deploy is confirmed not in use. Refer to KB 434126.
      • krbtgt: Do not rotate or modify. Refer to KB 444908.
      • It is not recommended to disable any of the accounts listed in the KB 407968.
      • System Groups: Retain ActAsUsers, CAAdmins, DCAdmins, and DCClients as they are essential for VMCA and host communication. Refer to this document for more details on the default groups and users.

Additional Information

  •  To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.