vsphere.local system accounts and groups cleanup guidance for vCenter Server
book
Article ID: 450189
calendar_today
Updated On:
Products
VMware vCenter ServerVMware Cloud Foundation
Issue/Introduction
Security audits in VMware Cloud Foundation (VCF) or standard vCenter Server environments may flag unused or "empty" groups and accounts in the vsphere.local domain. These identities are created automatically during bring-up, installation, or upgrades.
Auditor flags "weak maintenance" on local accounts/groups.
Numerous waiter-xxxx or krbtgt accounts appear in the SSO domain.
Groups such as ActAsUsers, CAAdmins, DCAdmins, and DCClients appear empty in the vSphere UI.
Environment
VMware vCenter Server
VMware Cloud Foundation
Cause
These identities are internal system service principals required for service isolation, Kerberos authentication, and certificate management. Many groups contain "Solution Users" that are hidden from the standard vSphere Client UI.
Resolution
Do not delete or modify these system-generated groups and accounts. Removal causes environment instability, authentication failures, and blocks future lifecycle management (LCM) tasks.
Identify Internal Systesm Accounts: Run the vCenter command to list system service accounts: # /usr/lib/vmware-vmafd/bin/dir-cli svcaccount list
Verify Internal Group Membership: View hidden solution users within the groups of interest: # /usr/lib/vmware-vmafd/bin/dir-cli group list --name CAAdmins
Refer to the following KBs and documentation for more information:
waiter-xxxx: Used by Auto Deploy. Disable only if Auto Deploy is confirmed not in use. Refer to KB 434126.
krbtgt: Do not rotate or modify. Refer to KB 444908.
It is not recommended to disable any of the accounts listed in the KB 407968.
System Groups: Retain ActAsUsers, CAAdmins, DCAdmins, and DCClients as they are essential for VMCA and host communication. Refer to this document for more details on the default groups and users.
Additional Information
To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.